CVE-2005-2951
AzDGDatingLite 2.1.3 - Remote Code Execution via Directory Traversal in l Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2005-2951. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets AzDGDatingLite V 2.1.3 (and possibly prior versions) by leveraging a remote code execution vulnerability. It registers a user and uploads a malicious JPEG file to achieve command execution on the target system.
Description
Directory traversal vulnerability in security.inc.php in AzDGDatingLite 2.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP commands via ".." sequences and "%00" (trailing null byte) characters in the l parameter, which is used in an include_once statement.
Exploits (1)
This exploit targets AzDGDatingLite V 2.1.3 (and possibly prior versions) by leveraging a remote code execution vulnerability. It registers a user and uploads a malicious JPEG file to achieve command execution on the target system.