CVE-2008-4735
CoAST 0.95 - Remote Code Execution via sections_file Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4735. PoCs published by DaRkLiFe.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in The Concord Asset, Software, and Ticket system (CoAST) 0.95. The vulnerability is due to improper input validation in the 'sections_file' parameter in header.php, allowing remote file inclusion.
Description
PHP remote file inclusion vulnerability in header.php in Concord Asset, Software, and Ticket system (CoAST) 0.95 allows remote attackers to execute arbitrary PHP code via a URL in the sections_file parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in The Concord Asset, Software, and Ticket system (CoAST) 0.95. The vulnerability is due to improper input validation in the 'sections_file' parameter in header.php, allowing remote file inclusion.