CVE-2008-2695
phpinv 0.8.0 - Remote File Inclusion via Action Parameter Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2695. PoCs published by CWH Underground.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in PHPInv 0.8.0 via the 'action' parameter in entry.php, allowing arbitrary file inclusion. It also includes an XSS vulnerability in search.php via the 'keyword' parameter.
Description
Directory traversal vulnerability in entry.php in phpInv 0.8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in PHPInv 0.8.0 via the 'action' parameter in entry.php, allowing arbitrary file inclusion. It also includes an XSS vulnerability in search.php via the 'keyword' parameter.