CVE-2008-1799
sabros.us 1.75 - Path Traversal via thumbnails.php img Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1799. PoCs published by HaCkeR_EgY.
AI-analyzed exploit summary This exploit demonstrates a remote file disclosure vulnerability in Sabrosus 1.75 via the 'thumbnails.php' script, which allows arbitrary file reads due to improper input validation in the 'img' parameter. The PoC includes example URLs to read sensitive files like 'config.php' or '/etc/passwd'.
Description
Directory traversal vulnerability in thumbnails.php in sabros.us 1.75 allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter.
Exploits (1)
This exploit demonstrates a remote file disclosure vulnerability in Sabrosus 1.75 via the 'thumbnails.php' script, which allows arbitrary file reads due to improper input validation in the 'img' parameter. The PoC includes example URLs to read sensitive files like 'config.php' or '/etc/passwd'.