CVE-2008-3194
pluck 4.5.1 - Path Traversal via langpref file blogpost or cat Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3194. PoCs published by BugReport.IR.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Pluck CMS 4.5.1. The vulnerability arises from improper input validation in predefined_variables.php, allowing arbitrary file inclusion via the blogpost parameter.
Description
Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) langpref, (2) file, (3) blogpost, or (4) cat parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Pluck CMS 4.5.1. The vulnerability arises from improper input validation in predefined_variables.php, allowing arbitrary file inclusion via the blogpost parameter.