Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6423. PoCs published by mozi.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in PassWiki, allowing an attacker to read arbitrary files (e.g., /etc/passwd) by manipulating the 'site_id' parameter with relative path traversal sequences. The PoC includes example URLs targeting vulnerable instances.
Description
Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arbitrary local files via a .. (dot dot) in the site_id parameter.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in PassWiki, allowing an attacker to read arbitrary files (e.g., /etc/passwd) by manipulating the 'site_id' parameter with relative path traversal sequences. The PoC includes example URLs targeting vulnerable instances.