Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-0489. PoCs published by p4imi0.
AI-analyzed exploit summary This exploit demonstrates a local file inclusion vulnerability in ClanSphere 2007.4.4 by using directory traversal sequences to access sensitive files like /etc/passwd. The vulnerability arises from improper input sanitization in the 'lang' parameter of install.php.
Description
Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
Exploits (1)
This exploit demonstrates a local file inclusion vulnerability in ClanSphere 2007.4.4 by using directory traversal sequences to access sensitive files like /etc/passwd. The vulnerability arises from improper input sanitization in the 'lang' parameter of install.php.