CVE-2008-6253
Pluck 4.5.3 - Remote Code Execution via g_pcltar_lib_dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6253. PoCs published by DSecRG.
AI-analyzed exploit summary The advisory describes a Local File Include (LFI) vulnerability in Pluck CMS 4.5.3, where the script `data/inc/lib/pcltar.lib.php` allows arbitrary file inclusion via the `g_pcltar_lib_dir` parameter when `register_globals` is enabled. The example provided demonstrates path traversal to read `/etc/passwd`.
Description
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the g_pcltar_lib_dir parameter.
Exploits (1)
The advisory describes a Local File Include (LFI) vulnerability in Pluck CMS 4.5.3, where the script `data/inc/lib/pcltar.lib.php` allows arbitrary file inclusion via the `g_pcltar_lib_dir` parameter when `register_globals` is enabled. The example provided demonstrates path traversal to read `/etc/passwd`.