CVE-2008-3562
Chupix CMS 0.1.0 - Path Traversal via Contact Module mods Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3562. PoCs published by casper41.
AI-analyzed exploit summary The provided text describes a local file inclusion (LFI) vulnerability in the Contact module for Chupix CMS. It outlines the vulnerability's cause (improper input sanitization) and provides example URLs for exploitation.
Description
Directory traversal vulnerability in index.php in the Contact module in Chupix CMS 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mods parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The provided text describes a local file inclusion (LFI) vulnerability in the Contact module for Chupix CMS. It outlines the vulnerability's cause (improper input sanitization) and provides example URLs for exploitation.