CVE-2008-0442
Small Axe Weblog 0.3.1 - Remote Code Execution via ffile Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0442. PoCs published by RoMaNcYxHaCkEr.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Small Axe Weblog 0.3.1 via the 'cfile' parameter in 'linkbar.php'. The vulnerability allows an attacker to include and execute arbitrary remote files, leading to potential remote code execution (RCE).
Description
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the ffile parameter, a different vector than CVE-2008-0376. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Small Axe Weblog 0.3.1 via the 'cfile' parameter in 'linkbar.php'. The vulnerability allows an attacker to include and execute arbitrary remote files, leading to potential remote code execution (RCE).