CVE-2008-0423
Lama Software - Remote Code Execution via MY_CONF[classRoot] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0423. PoCs published by QTRinux.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Lama Software kostenlos by manipulating the MY_CONF[classRoot] parameter to include arbitrary files. The PoC provides specific paths for exploitation.
Description
Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[classRoot] parameter to (1) inc.steps.access_error.php, (2) inc.steps.check_login.php, or (3) inc.steps.init_system.php in admin/functions/.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Lama Software kostenlos by manipulating the MY_CONF[classRoot] parameter to include arbitrary files. The PoC provides specific paths for exploitation.