CVE-2008-4720
The Gemini Portal 4.7 - Remote Code Execution via Lang Parameter File Inclusion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4720. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates a local file inclusion vulnerability in Gemini Portal 4.7, allowing an attacker to include arbitrary files via the 'lang' parameter in two PHP scripts. The PoC provides direct URLs to exploit the vulnerability.
Description
Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) page/forums/bottom.php and (2) page/forums/category.php.
Exploits (1)
This exploit demonstrates a local file inclusion vulnerability in Gemini Portal 4.7, allowing an attacker to include arbitrary files via the 'lang' parameter in two PHP scripts. The PoC provides direct URLs to exploit the vulnerability.