CVE-2008-5936
mini-pub <= 0.3 - Unauthenticated Arbitrary File Read via sFileName Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5936. PoCs published by GoLd_M.
AI-analyzed exploit summary The exploit demonstrates two vulnerabilities in mini-pub.php v0.3: a local directory traversal via the 'sDir' parameter and a file disclosure via the 'sFileName' parameter. Both POCs are provided with clear paths to exploit the flaws.
Description
front-end/edit.php in mini-pub 0.3 and earlier allows remote attackers to read files and obtain PHP source code via a filename in the sFileName parameter.
Exploits (1)
The exploit demonstrates two vulnerabilities in mini-pub.php v0.3: a local directory traversal via the 'sDir' parameter and a file disclosure via the 'sFileName' parameter. Both POCs are provided with clear paths to exploit the flaws.