Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-4667. PoCs published by JIKO.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the specified software. It allows an attacker to read arbitrary files on the server by manipulating the 'rss' parameter in the URL, potentially leading to information disclosure or remote code execution if combined with log poisoning or other techniques.
Description
Directory traversal vulnerability in rss.php in ArabCMS 2.0 beta 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the rss parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the specified software. It allows an attacker to read arbitrary files on the server by manipulating the 'rss' parameter in the URL, potentially leading to information disclosure or remote code execution if combined with log poisoning or other techniques.