CVE-2008-2459
EntertainmentScript 1.4.0 - Path Traversal via Page Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2459. PoCs published by Stack.
AI-analyzed exploit summary This exploit targets a Local File Inclusion (LFI) vulnerability in EntertainmentScript V1.4.0, allowing an attacker to inject PHP code into log files and execute arbitrary commands via a crafted request to page.php.
Description
Directory traversal vulnerability in page.php in EntertainmentScript 1.4.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.
Exploits (1)
This exploit targets a Local File Inclusion (LFI) vulnerability in EntertainmentScript V1.4.0, allowing an attacker to inject PHP code into log files and execute arbitrary commands via a crafted request to page.php.