CVE-2008-4490
phpabook < 0.8.8b - Remote File Inclusion via UserInfo Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4490. PoCs published by JosS.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in phpAbook <= 0.8.8b via cookie manipulation. The 'userLang' parameter in the 'userInfo' cookie is exploited to include arbitrary files due to insufficient input validation.
Description
Directory traversal vulnerability in config.inc.php in phpAbook 0.8.8b and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the userInfo cookie.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in phpAbook <= 0.8.8b via cookie manipulation. The 'userLang' parameter in the 'userInfo' cookie is exploited to include arbitrary files due to insufficient input validation.