CVE-2008-2839
Traindepot 0.1 - Cross-Site Scripting via Search Query Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2839. PoCs published by CWH Underground.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Traindepot 0.1, allowing an attacker to read arbitrary files (e.g., boot.ini or /etc/passwd) via path traversal. It also includes a Cross-Site Scripting (XSS) vulnerability in the search module, which can be triggered via a POST request with a malicious script payload.
Description
Cross-site scripting (XSS) vulnerability in the search module in Traindepot 0.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter to index.php.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Traindepot 0.1, allowing an attacker to read arbitrary files (e.g., boot.ini or /etc/passwd) via path traversal. It also includes a Cross-Site Scripting (XSS) vulnerability in the search module, which can be triggered via a POST request with a malicious script payload.