Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6582. PoCs published by irk4z.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in mBlog 1.2, allowing remote file disclosure via path manipulation in the 'page' parameter. The PoC uses URL-encoded traversal sequences to access sensitive files like 'db_config.php' or '/etc/passwd'.
Description
Directory traversal vulnerability in index.php in mBlog 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter in a page mode action.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in mBlog 1.2, allowing remote file disclosure via path manipulation in the 'page' parameter. The PoC uses URL-encoded traversal sequences to access sensitive files like 'db_config.php' or '/etc/passwd'.