CVE-2008-6335
eMetrix Online Keyword Research Tool - Path Traversal via Download Filename Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6335. PoCs published by Cold Zero.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the 'download.php' script of Online Keyword Research software. By manipulating the 'filename' parameter with directory traversal sequences, an attacker can read arbitrary files on the server, such as '/etc/passwd'.
Description
Directory traversal vulnerability in download.php in eMetrix Online Keyword Research Tool allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the 'download.php' script of Online Keyword Research software. By manipulating the 'filename' parameter with directory traversal sequences, an attacker can read arbitrary files on the server, such as '/etc/passwd'.