Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3481. PoCs published by EgiX.
AI-analyzed exploit summary This exploit leverages a Local File Inclusion (LFI) vulnerability in Coppermine Photo Gallery <= 1.4.18, allowing remote code execution by manipulating the USER['lang'] cookie parameter to include arbitrary local files. The exploit includes a full interactive shell for post-exploitation.
Description
themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
Exploits (1)
This exploit leverages a Local File Inclusion (LFI) vulnerability in Coppermine Photo Gallery <= 1.4.18, allowing remote code execution by manipulating the USER['lang'] cookie parameter to include arbitrary local files. The exploit includes a full interactive shell for post-exploitation.