CVE-2008-1696
DaZPHPNews 0.1-1 - Path Traversal via makepost.php prefixdir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1696. PoCs published by w0cker.
AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in DaZPHP to read arbitrary files by manipulating the 'prefixdir' parameter. The example demonstrates reading '/etc/passwd' via path traversal.
Description
Directory traversal vulnerability in makepost.php in DaZPHPNews 0.1-1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the prefixdir parameter.
Exploits (1)
This exploit leverages a directory traversal vulnerability in DaZPHP to read arbitrary files by manipulating the 'prefixdir' parameter. The example demonstrates reading '/etc/passwd' via path traversal.