Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6604. PoCs published by gmda.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in picoflatcms 0.5.9 due to improper input validation. The PoC shows how to traverse directories and disclose sensitive files like boot.ini.
Description
Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagina parameter, a different vulnerability than CVE-2007-5390.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in picoflatcms 0.5.9 due to improper input validation. The PoC shows how to traverse directories and disclose sensitive files like boot.ini.