CVE-2008-5587
NUCLEIphppgadmin <= 4.2.1 - Path Traversal via _language Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5587. PoCs published by dun. A Nuclei detection template is also available.
AI-analyzed exploit summary This is a writeup detailing a Local File Inclusion (LFI) vulnerability in phpPgAdmin <= 4.2.1. The vulnerability arises from improper handling of the `_language` parameter, allowing an attacker to include arbitrary files via path traversal sequences.
Description
Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the _language parameter to index.php.
Exploits (1)
This is a writeup detailing a Local File Inclusion (LFI) vulnerability in phpPgAdmin <= 4.2.1. The vulnerability arises from improper handling of the `_language` parameter, allowing an attacker to include arbitrary files via path traversal sequences.
Nuclei Templates (1)
http.title:"phpPgAdmin" || http.title:phppgadmin || cpe:"cpe:2.3:a:phppgadmin_project:phppgadmin"
title=phppgadmin