CVE-2008-4702
phpwebgallery 1.3.4 - Path Traversal via user[language] or user[template] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4702. PoCs published by Khashayar Fereidani.
AI-analyzed exploit summary This is a vulnerability writeup detailing multiple Local File Inclusion (LFI) and Cross-Site Scripting (XSS) vulnerabilities in PhpWebGallery 1.3.4. It provides URLs for exploitation but does not include functional exploit code.
Description
Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) user[language] and (2) user[template] parameters to (a) init.inc.php, and (b) the user[language] parameter to isadmin.inc.php.
Exploits (1)
This is a vulnerability writeup detailing multiple Local File Inclusion (LFI) and Cross-Site Scripting (XSS) vulnerabilities in PhpWebGallery 1.3.4. It provides URLs for exploitation but does not include functional exploit code.