Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-4739. PoCs published by dun.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in PlugSpace v0.1. The vulnerability arises from unsanitized user input in the 'navi' parameter, allowing an attacker to include arbitrary files via directory traversal sequences.
Description
Directory traversal vulnerability in index.php in PlugSpace 0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the navi parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in PlugSpace v0.1. The vulnerability arises from unsanitized user input in the 'navi' parameter, allowing an attacker to include arbitrary files via directory traversal sequences.