CVE-2008-0542
Gerd Tentler Simple Forum 3.2 - Path Traversal via Thumbnail.php File Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0542. PoCs published by tomplixsee.
AI-analyzed exploit summary The exploit demonstrates XSS and remote file disclosure vulnerabilities in Simple Forum v3.2. The XSS is triggered via unsanitized 'open' and 'date_show' parameters, while the file disclosure leverages path traversal in 'thumbnail.php' to read arbitrary files.
Description
Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
Exploits (1)
The exploit demonstrates XSS and remote file disclosure vulnerabilities in Simple Forum v3.2. The XSS is triggered via unsanitized 'open' and 'date_show' parameters, while the file disclosure leverages path traversal in 'thumbnail.php' to read arbitrary files.