CVE-2006-4161
xennobb < 2.1.0 - Directory Traversal via Avatar Gallery Category Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4161. PoCs published by Chris Boulton.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in XennoBB by manipulating the 'category' parameter in the URL to access arbitrary files. The PoC shows how an attacker can traverse directories to retrieve sensitive files from the server.
Description
Directory traversal vulnerability in the avatar_gallery action in profile.php in XennoBB 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the category parameter.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in XennoBB by manipulating the 'category' parameter in the URL to access arbitrary files. The PoC shows how an attacker can traverse directories to retrieve sensitive files from the server.