CVE-2008-5204

PowerAward 1.1.0 RC1 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-5204. PoCs published by CraCkEr.

AI-analyzed exploit summary This exploit demonstrates Local File Inclusion (LFI) and Cross-Site Scripting (XSS) vulnerabilities in PowerAward 1.1.0 RC1. The LFI allows arbitrary file inclusion via the 'lang' parameter in multiple PHP scripts, while the XSS is triggered via the 'l_vote_done' parameter in external_vote.php.

Description

Multiple directory traversal vulnerabilities in PowerAward 1.1.0 RC1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the lang parameter to (1) agb.php, (2) angemeldet.php, (3) anmelden.php, (4) charts.php, (5) external_vote.php, (6) guestbook.php, (7) impressum.php, (8) index.php, (9) rss-reader.php, (10) statistic.php, (11) teilnehmer.php, (12) topsites.php, (13) votecode.php, (14) voting.php, and (15) winner.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by CraCkEr · textwebappsphp
https://www.exploit-db.com/exploits/5962

This exploit demonstrates Local File Inclusion (LFI) and Cross-Site Scripting (XSS) vulnerabilities in PowerAward 1.1.0 RC1. The LFI allows arbitrary file inclusion via the 'lang' parameter in multiple PHP scripts, while the XSS is triggered via the 'l_vote_done' parameter in external_vote.php.

Classification
Working Poc 90%
Attack Type
Lfi | Xss
Complexity
Trivial
Reliability
Reliable
Target: PowerAward 1.1.0 RC1
No auth needed
Prerequisites: Target application must be running PowerAward 1.1.0 RC1 · Register globals must be enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/29993
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5962
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43463

Scores

EPSS 0.0185
EPSS Percentile 76.3%

Details

CWE
CWE-22
Status published
Products (1)
poweraward/poweraward 1.1.0 rc1
Published Nov 21, 2008
Tracked Since Feb 18, 2026