CVE-2008-6126
moziloCMS <= 1.10.2 - Path Traversal via Download and Index Page Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6126.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in moziloCMS 1.11, including Local File Inclusion (LFI), Cross-Site Scripting (XSS), and Path Disclosure. It provides functional PoC URLs that can be used to exploit these vulnerabilities without requiring authentication.
Description
Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter to download.php and the (2) page parameter to index.php, a different vector than CVE-2008-3589.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in moziloCMS 1.11, including Local File Inclusion (LFI), Cross-Site Scripting (XSS), and Path Disclosure. It provides functional PoC URLs that can be used to exploit these vulnerabilities without requiring authentication.