CVE-2008-2913
Devalcms 1.4a - Remote File Inclusion and Path Traversal via func.php currentpath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2913. PoCs published by CWH Underground.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Devalcms 1.4a. The vulnerability arises due to insufficient sanitization of user input in the `mystriprelative` function, allowing path traversal sequences to bypass security checks and include arbitrary files.
Description
Directory traversal vulnerability in func.php in Devalcms 1.4a, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the currentpath parameter, in conjunction with certain ... (triple dot) and ..... sequences in the currentfile parameter, to index.php.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Devalcms 1.4a. The vulnerability arises due to insufficient sanitization of user input in the `mystriprelative` function, allowing path traversal sequences to bypass security checks and include arbitrary files.