CVE-2007-0335
Jax Petition Book 1.0.3.06 - Directory Traversal via Languagepack Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-0335. PoCs published by ilker Kandemir.
AI-analyzed exploit summary The provided text describes a local file inclusion (LFI) vulnerability in Jax Petitionbook 1.0.3.06, where unsanitized user input in the 'language' parameter allows directory traversal attacks. The example URL demonstrates how an attacker could include arbitrary local files.
Description
Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php.
Exploits (2)
The provided text describes a local file inclusion (LFI) vulnerability in Jax Petitionbook 1.0.3.06, where unsanitized user input in the 'language' parameter allows directory traversal attacks. The example URL demonstrates how an attacker could include arbitrary local files.
This exploit demonstrates a local file inclusion vulnerability in Jax Petitionbook 1.0.3.06 by leveraging directory traversal sequences to include arbitrary files. The PoC uses a null byte to bypass sanitization, allowing access to sensitive files.