Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-1040. PoCs published by r0ut3r.
AI-analyzed exploit summary This exploit targets a file disclosure vulnerability in XNews 1.0.1 by manipulating the 'xnews-template' parameter to read arbitrary files (e.g., userdb.php). It sends a crafted HTTP GET request to leak usernames and MD5 hashes.
Description
Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter.
Exploits (1)
This exploit targets a file disclosure vulnerability in XNews 1.0.1 by manipulating the 'xnews-template' parameter to read arbitrary files (e.g., userdb.php). It sends a crafted HTTP GET request to leak usernames and MD5 hashes.