CVE-2008-4158
Zanfi CMS lite 1.2 - Path Traversal via Flag or Inc Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4158. PoCs published by SirGod.
AI-analyzed exploit summary The exploit demonstrates a Local File Inclusion (LFI) vulnerability in Zanfi CMS lite / Jaw Portal free via the 'flag' and 'inc' parameters in index.php. The PoC shows how an attacker can include arbitrary local files by appending a null byte (%00) to bypass file extension checks.
Description
Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) flag and (2) inc parameters.
Exploits (1)
The exploit demonstrates a Local File Inclusion (LFI) vulnerability in Zanfi CMS lite / Jaw Portal free via the 'flag' and 'inc' parameters in index.php. The PoC shows how an attacker can include arbitrary local files by appending a null byte (%00) to bypass file extension checks.