CVE-2008-4319
Libra PHP File Manager < 1.18 - Improper Authentication Bypass via Query String Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4319. PoCs published by Pepelux.
AI-analyzed exploit summary This Perl script exploits a Local File Inclusion (LFI) vulnerability in Libra PHP File Manager <= 1.18 via the 'fileadmin.php' script. It allows an attacker to list directories or read arbitrary files by manipulating the 'folder' and 'fename' parameters.
Description
fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.
Exploits (1)
This Perl script exploits a Local File Inclusion (LFI) vulnerability in Libra PHP File Manager <= 1.18 via the 'fileadmin.php' script. It allows an attacker to list directories or read arbitrary files by manipulating the 'folder' and 'fename' parameters.