CVE-2008-1557
BolinOS 4.6.1 - Exposure of Sensitive Information via phpinfo Page
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1557. PoCs published by DSecRG.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in BolinOS 4.6.1, including Local File Include (LFI), Cross-Site Scripting (XSS), and system information disclosure. The LFI allows arbitrary file reading via path traversal, while XSS vulnerabilities are present in both GET and POST parameters.
Description
BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/contentFiles/gBphpInfo.php, which calls the phpinfo function.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in BolinOS 4.6.1, including Local File Include (LFI), Cross-Site Scripting (XSS), and system information disclosure. The LFI allows arbitrary file reading via path traversal, while XSS vulnerabilities are present in both GET and POST parameters.