CVE-2008-5593

Mini CMS 1.0.1 - Remote File Inclusion via Page and Admin Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-5593. PoCs published by cOndemned.

AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Mini-CMS 1.0.1 due to improper input validation in the 'page' and 'admin' parameters. The PoC shows how an attacker can traverse directories and include arbitrary local files using path traversal sequences.

Description

Multiple directory traversal vulnerabilities in index.php in Mini CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by cOndemned · textwebappsphp
https://www.exploit-db.com/exploits/7375

This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Mini-CMS 1.0.1 due to improper input validation in the 'page' and 'admin' parameters. The PoC shows how an attacker can traverse directories and include arbitrary local files using path traversal sequences.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Mini-CMS 1.0.1
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7375
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4750
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32680
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33024

Scores

EPSS 0.0243
EPSS Percentile 82.1%

Details

CWE
CWE-22
Status published
Products (1)
bpowerhouse/mini_cms 1.0.1
Published Dec 16, 2008
Tracked Since Feb 18, 2026