Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2368. PoCs published by Trex.
AI-analyzed exploit summary The code describes two file disclosure vulnerabilities in WebSPELL <= 4.01.02 via the 'picture.php' script. Vulnerability 1 requires 'register_globals' to be enabled, while Vulnerability 2 relies on PHP versions < 4.3.0. Both allow arbitrary file reads via path traversal.
Description
picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.
Exploits (1)
The code describes two file disclosure vulnerabilities in WebSPELL <= 4.01.02 via the 'picture.php' script. Vulnerability 1 requires 'register_globals' to be enabled, while Vulnerability 2 relies on PHP versions < 4.3.0. Both allow arbitrary file reads via path traversal.