CVE-2008-2341
News Manager 2.0 - Remote Code Execution via ch_readalso.php read_xml_include Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2341. PoCs published by GoLd_M.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in News Manager 2.0, including remote file inclusion, file disclosure, SQL injection, permission bypass, and information leakage via PHPINFO. It provides specific endpoints and payloads for exploitation.
Description
PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the read_xml_include parameter.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in News Manager 2.0, including remote file inclusion, file disclosure, SQL injection, permission bypass, and information leakage via PHPINFO. It provides specific endpoints and payloads for exploitation.