Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3293. PoCs published by Ghost Hacker.
AI-analyzed exploit summary This exploit leverages a file disclosure vulnerability in EZWebAlbum's download.php script due to improper input validation. The script directly passes user-controlled input to the readfile() function, allowing arbitrary file reads.
Description
Directory traversal vulnerability in download.php in EZWebAlbum allows remote attackers to read arbitrary files via the dlfilename parameter.
Exploits (1)
This exploit leverages a file disclosure vulnerability in EZWebAlbum's download.php script due to improper input validation. The script directly passes user-controlled input to the readfile() function, allowing arbitrary file reads.