CVE-2008-5748
HIGHBloofoxCMS 0.3.4 - Path Traversal via Lang Theme or Module Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5748. PoCs published by fuzion.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in BloofoxCMS 0.3.4. It leverages improper input validation in the `dialog.php` file to include arbitrary files, such as `/etc/passwd`, by manipulating the `lang`, `theme`, or `module` parameters.
Description
Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in BloofoxCMS 0.3.4. It leverages improper input validation in the `dialog.php` file to include arbitrary files, such as `/etc/passwd`, by manipulating the `lang`, `theme`, or `module` parameters.
References (6)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H