CVE-2008-3371
TalkBack < 2.3.6.2 - Remote File Inclusion via Language Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2008-3371. PoCs published by JIKO, SirGod, NoGe.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in TalkBack 2.3.14, including command injection via the 'result' parameter in 'import.php' and local file inclusion via the 'language' parameter in 'help.php'. The PoC provides clear instructions and code snippets for exploitation.
Description
Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.
Exploits (3)
This exploit demonstrates multiple vulnerabilities in TalkBack 2.3.14, including command injection via the 'result' parameter in 'import.php' and local file inclusion via the 'language' parameter in 'help.php'. The PoC provides clear instructions and code snippets for exploitation.
The exploit demonstrates local file inclusion (LFI) and PHP info disclosure vulnerabilities in Talkback 2.3.6. It provides functional PoC URLs to read arbitrary files via path traversal and null byte injection, as well as a direct endpoint for PHP configuration exposure.
The exploit demonstrates a Local File Inclusion (LFI) vulnerability in TalkBack 2.3.5 via the 'language' parameter in install/help.php. The vulnerable code includes a user-controlled file path without proper sanitization, allowing arbitrary file inclusion via null byte termination.