Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6726. PoCs published by SirGod.
AI-analyzed exploit summary The exploit demonstrates SQL injection and local file inclusion vulnerabilities in CMScout 2.06. It provides specific payloads for authenticated users to extract credentials and read arbitrary files via path traversal.
Description
Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bit parameter to (1) admin.php and (2) index.php, different vectors than CVE-2008-3415.
Exploits (1)
The exploit demonstrates SQL injection and local file inclusion vulnerabilities in CMScout 2.06. It provides specific payloads for authenticated users to extract credentials and read arbitrary files via path traversal.