Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3390. PoCs published by DSecRG.
AI-analyzed exploit summary This exploit demonstrates a Local File Include (LFI) vulnerability in Minishowcase Image Gallery v09b136 via the 'lang' parameter in 'libraries/general.init.php'. It requires 'register_globals' to be enabled and allows reading arbitrary files (e.g., '/etc/passwd') by traversing directories.
Description
Directory traversal vulnerability in libraries/general.init.php in Minishowcase Image Gallery 09b136, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
Exploits (1)
This exploit demonstrates a Local File Include (LFI) vulnerability in Minishowcase Image Gallery v09b136 via the 'lang' parameter in 'libraries/general.init.php'. It requires 'register_globals' to be enabled and allows reading arbitrary files (e.g., '/etc/passwd') by traversing directories.