CVE-2005-2892
PBLang 4.65 - Directory Traversal via setcookie.php u Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-2892. PoCs published by rgod, Number 7.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in PBLang via the 'u' parameter in setcookie.php, allowing unauthorized access to sensitive files like /etc/passwd. The vulnerability arises from insufficient input sanitization.
Description
Directory traversal vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) in the u parameter.
Exploits (2)
This exploit demonstrates a directory traversal vulnerability in PBLang via the 'u' parameter in setcookie.php, allowing unauthorized access to sensitive files like /etc/passwd. The vulnerability arises from insufficient input sanitization.
This is a writeup describing a local file inclusion vulnerability in PBLang 4.67.16.a. The vulnerability allows an attacker to read arbitrary files by manipulating the 'u' parameter in setcookie.php.