Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-5794. PoCs published by cOndemned.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file deletion vulnerability in LoveCMS 1.6.2 Final. The vulnerability arises from improper handling of the 'delete' parameter in the GET request, allowing path traversal to delete files outside the intended directory.
Description
Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.
Exploits (1)
This exploit demonstrates an arbitrary file deletion vulnerability in LoveCMS 1.6.2 Final. The vulnerability arises from improper handling of the 'delete' parameter in the GET request, allowing path traversal to delete files outside the intended directory.