CVE-2008-5291
fuzzylime_cms 3.03 - Remote File Inclusion via Track.php p Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5291. PoCs published by Alfons Luja.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in FuzzyLime 3.03 via the 'track.php' script. The 'p' parameter is not properly sanitized, allowing an attacker to include arbitrary local files when POST data is provided.
Description
Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter, a different vector than CVE-2007-4805 and CVE-2008-3165.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in FuzzyLime 3.03 via the 'track.php' script. The 'p' parameter is not properly sanitized, allowing an attacker to include arbitrary local files when POST data is provided.