Record summary

CVE-2008-5678 has a selected CVSS score of 4.0; EIP currently links 1 catalogued exploit.

Description

Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile parameter to the default URI under cgi/, as demonstrated by the (1) get_settings.ini, (2) setup.ini, and (3) text.ini files.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBOLIB 7 WebView 2.5.1.1 - 'infile' Local File InclusionExploitDB exploitby ZeNNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

5