Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-2895. PoCs published by SkyOut.
AI-analyzed exploit summary This is a detailed writeup describing a Local File Inclusion (LFI) vulnerability in Aprox CMS Engine v5.1.0.4. The exploit leverages improper input validation in the 'page' parameter to include arbitrary files via directory traversal and null byte injection.
Description
Directory traversal vulnerability in index.php in AproxEngine 5.1.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
Exploits (1)
This is a detailed writeup describing a Local File Inclusion (LFI) vulnerability in Aprox CMS Engine v5.1.0.4. The exploit leverages improper input validation in the 'page' parameter to include arbitrary files via directory traversal and null byte injection.