CVE-2008-3415
CMScout 2.05 - Remote File Inclusion via Directory Traversal in bit Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3415. PoCs published by Khashayar Fereidani.
AI-analyzed exploit summary This is a writeup describing a Local File Inclusion (LFI) vulnerability in CMScout 2.05. It provides a proof-of-concept URL and suggests a method to achieve remote code execution by uploading a malicious image file as an avatar.
Description
Directory traversal vulnerability in common.php in CMScout 2.05, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bit parameter, as demonstrated by an upload to avatar/ of a .jpg file containing PHP sequences.
Exploits (1)
This is a writeup describing a Local File Inclusion (LFI) vulnerability in CMScout 2.05. It provides a proof-of-concept URL and suggests a method to achieve remote code execution by uploading a malicious image file as an avatar.