CVE-2008-4115
TalkBack 2.3.6 - Unauthenticated Sensitive Information Exposure via info.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4115. PoCs published by SirGod.
AI-analyzed exploit summary The exploit demonstrates local file inclusion (LFI) and PHP info disclosure vulnerabilities in Talkback 2.3.6. It provides functional PoC URLs to read arbitrary files via path traversal and null byte injection, as well as a direct endpoint for PHP configuration exposure.
Description
TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.
Exploits (1)
The exploit demonstrates local file inclusion (LFI) and PHP info disclosure vulnerabilities in Talkback 2.3.6. It provides functional PoC URLs to read arbitrary files via path traversal and null byte injection, as well as a direct endpoint for PHP configuration exposure.