CVE-2008-2215
Project-Based Calendaring System 0.7.1-1 - Path Traversal via Filename Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2215. PoCs published by GoLd_M.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Project Based Calendaring System (PBCS) 0.7.1, including remote file upload, remote file disclosure, and local file inclusion. It provides specific URLs and parameters to exploit these vulnerabilities.
Description
Multiple directory traversal vulnerabilities in Project-Based Calendaring System (PBCS) 0.7.1-1 allow remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to (1) src/yopy_sync.php and (2) system-logger/print_logs.php.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Project Based Calendaring System (PBCS) 0.7.1, including remote file upload, remote file disclosure, and local file inclusion. It provides specific URLs and parameters to exploit these vulnerabilities.