CVE-2008-6407
ol'bookmarks manager 0.7.5 - Path Traversal via frame.php framefile Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6407. PoCs published by GoLd_M.
AI-analyzed exploit summary This exploit demonstrates RFI, LFI, and SQL injection vulnerabilities in Ol Bookmarks Manager 0.7.5. The RFI and LFI are due to unsanitized user input in the 'framefile' parameter, while the SQL injection is in the 'id' parameter of index.php.
Description
Directory traversal vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the framefile parameter.
Exploits (1)
This exploit demonstrates RFI, LFI, and SQL injection vulnerabilities in Ol Bookmarks Manager 0.7.5. The RFI and LFI are due to unsanitized user input in the 'framefile' parameter, while the SQL injection is in the 'id' parameter of index.php.