CVE-2008-1624
Jshop Server 1.x-2.x - Remote File Inclusion via xPage Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1624. PoCs published by v0l4arrra.
AI-analyzed exploit summary This exploit demonstrates a local file inclusion vulnerability in JShop Server 1.x-2.x, allowing arbitrary file reading and potential remote code execution via log poisoning. The PoC includes steps to read sensitive files and inject PHP code into logs for execution.
Description
Directory traversal vulnerability in v2demo/page.php in Jshop Server 1.x through 2.x allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xPage parameter.
Exploits (1)
This exploit demonstrates a local file inclusion vulnerability in JShop Server 1.x-2.x, allowing arbitrary file reading and potential remote code execution via log poisoning. The PoC includes steps to read sensitive files and inject PHP code into logs for execution.