CVE-2008-0703
sflog < 0.96 - Path Traversal via Permalink or Section Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0703. PoCs published by muuratsalo.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in sflog! 0.96, allowing remote attackers to disclose arbitrary files by manipulating the 'permalink' or 'section' parameters.
Description
Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) permalink or (2) section parameter to index.php, possibly involving includes/entries.inc.php and other files included by index.php.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in sflog! 0.96, allowing remote attackers to disclose arbitrary files by manipulating the 'permalink' or 'section' parameters.