CVE-2008-6271
tbmnetcms 1.0 - Path Traversal via Index.php Content Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6271. PoCs published by d3v1l.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in TBmnetCMS v1.0 via the 'content' parameter in index.php. The PoC uses directory traversal sequences to access sensitive files like /etc/passwd, requiring specific PHP configurations (magic_quotes=OFF, disable_functions=ini_set).
Description
Directory traversal vulnerability in index.php in TBmnetCMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the content parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in TBmnetCMS v1.0 via the 'content' parameter in index.php. The PoC uses directory traversal sequences to access sensitive files like /etc/passwd, requiring specific PHP configurations (magic_quotes=OFF, disable_functions=ini_set).