CVE-2008-6551

e-vision CMS <= 2.0.2 - Path Traversal via Adminlang Cookie or Module Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6551. PoCs published by StAkeR.

AI-analyzed exploit summary This exploit targets a Local File Inclusion (LFI) vulnerability in e-Vision <= 2.0.2 by manipulating the 'module' parameter in various admin scripts to read arbitrary files. It checks for Magic Quotes GPC and attempts to exploit the vulnerability via multiple endpoints.

Description

Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) an adminlang cookie to admin/ind_ex.php; or the module parameter to (2) 3rdparty/adminpart/add3rdparty.php, (3) polling/adminpart/addpolling.php, (4) contact/adminpart/addcontact.php, (5) brandnews/adminpart/addbrandnews.php, (6) newsletter/adminpart/addnewsletter.php, (7) game/adminpart/addgame.php, (8) tour/adminpart/addtour.php, (9) articles/adminpart/addarticles.php, (10) product/adminpart/addproduct.php, or (11) plain/adminpart/addplain.php in modules/.

Exploits (1)

exploitdb WORKING POC VERIFIED
by StAkeR · phpwebappsphp
https://www.exploit-db.com/exploits/7031

This exploit targets a Local File Inclusion (LFI) vulnerability in e-Vision <= 2.0.2 by manipulating the 'module' parameter in various admin scripts to read arbitrary files. It checks for Magic Quotes GPC and attempts to exploit the vulnerability via multiple endpoints.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: e-Vision <= 2.0.2
No auth needed
Prerequisites: Magic Quotes GPC turned off · Access to vulnerable endpoints
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46457
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32180
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7031

Scores

EPSS 0.0191
EPSS Percentile 77.1%

Details

CWE
CWE-22
Status published
Products (2)
e-vision/e-vision_cms 1.0
e-vision/e-vision_cms < 2.02
Published Mar 30, 2009
Tracked Since Feb 18, 2026