CVE-2008-2343
News Manager 2.0 - Information Disclosure via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2343. PoCs published by GoLd_M.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in News Manager 2.0, including remote file inclusion, file disclosure, SQL injection, permission bypass, and information leakage via PHPINFO. It provides specific endpoints and payloads for exploitation.
Description
News Manager 2.0 allows remote attackers to bypass restrictions and obtain sensitive information via a direct request to (1) db/connect_str.php and (2) login/info.php.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in News Manager 2.0, including remote file inclusion, file disclosure, SQL injection, permission bypass, and information leakage via PHPINFO. It provides specific endpoints and payloads for exploitation.