CVE-2008-4425
Phlatline Personal Information Manager 1.0 - Path Traversal & Arbitrary File Deletion via Upload.php
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2008-4425. PoCs published by BeyazKurt.
AI-analyzed exploit summary The exploit demonstrates a file deletion vulnerability in Ppim v1.0 via the 'upload.php' script and an XSS vulnerability in 'events.php'. It provides clear examples of malicious URLs to trigger these vulnerabilities.
Description
Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter within a delfile action.
Exploits (3)
The exploit demonstrates a file deletion vulnerability in Ppim v1.0 via the 'upload.php' script and an XSS vulnerability in 'events.php'. It provides clear examples of malicious URLs to trigger these vulnerabilities.
The exploit demonstrates two vulnerabilities in Ppim v1.0: an unauthenticated password change and an arbitrary file upload leading to remote code execution. The PoC provides direct URLs and steps to exploit these flaws.
This is a detailed technical analysis of multiple vulnerabilities in pPIM 1.0, including authentication bypass, arbitrary file upload, command execution, and credential exposure. The writeup provides specific examples and Perl scripts to demonstrate the flaws.