CVE-2008-2342
News Manager 2.0 - Path Traversal via Attachments.php ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2342. PoCs published by GoLd_M.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in News Manager 2.0, including remote file inclusion, file disclosure, SQL injection, permission bypass, and information leakage via PHPINFO. It provides specific endpoints and payloads for exploitation.
Description
Directory traversal vulnerability in attachments.php in News Manager 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in News Manager 2.0, including remote file inclusion, file disclosure, SQL injection, permission bypass, and information leakage via PHPINFO. It provides specific endpoints and payloads for exploitation.