CVE-2008-6108
Galatolo WebManager 1.0 - Cross-Site Scripting via result.php key Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6108. PoCs published by StAkeR.
AI-analyzed exploit summary This exploit targets a remote command execution vulnerability in Galatolo Web Manager 1.0 by injecting malicious PHP code into log files via the User-Agent header and then executing arbitrary commands through the vulnerable application. It automates the discovery of log file paths and provides an interactive shell.
Description
Cross-site scripting (XSS) vulnerability in result.php in Galatolo WebManager (GWM) 1.0 allows remote attackers to inject arbitrary web script or HTML via the key parameter.
Exploits (1)
This exploit targets a remote command execution vulnerability in Galatolo Web Manager 1.0 by injecting malicious PHP code into log files via the User-Agent header and then executing arbitrary commands through the vulnerable application. It automates the discovery of log file paths and provides an interactive shell.