CVE-2007-1933
dreamcodes pcp-guestbook 3.0 - Directory Traversal via Lang Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1933. PoCs published by Dj7xpl.
AI-analyzed exploit summary This is a writeup describing a local file inclusion (LFI) vulnerability in PcP-Book 3.0. The vulnerability allows an attacker to include arbitrary files via null byte injection in the 'lang' parameter.
Description
Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php.
Exploits (1)
This is a writeup describing a local file inclusion (LFI) vulnerability in PcP-Book 3.0. The vulnerability allows an attacker to include arbitrary files via null byte injection in the 'lang' parameter.