CVE-2007-4585
2532gigs 1.2.1 - Remote File Inclusion via Language Parameter Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4585. PoCs published by bd0rk.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in 2532|Gigs 1.2.1 via the 'activateuser.php' script. The vulnerability arises from unsanitized user input in the 'language' parameter, allowing path traversal to include arbitrary files.
Description
Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in 2532|Gigs 1.2.1 via the 'activateuser.php' script. The vulnerability arises from unsanitized user input in the 'language' parameter, allowing path traversal to include arbitrary files.