Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-1158. PoCs published by D. Matscheko.
AI-analyzed exploit summary This exploit demonstrates a local file inclusion (LFI) vulnerability in Pagesetter 6.3.0 beta 5 and prior versions. The vulnerability arises from improper sanitization of user-supplied input in the 'id' parameter, allowing an attacker to traverse directories and include arbitrary files.
Description
Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.
Exploits (1)
This exploit demonstrates a local file inclusion (LFI) vulnerability in Pagesetter 6.3.0 beta 5 and prior versions. The vulnerability arises from improper sanitization of user-supplied input in the 'id' parameter, allowing an attacker to traverse directories and include arbitrary files.