Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6842. PoCs published by Alfons Luja.
AI-analyzed exploit summary This exploit targets a Local File Inclusion (LFI) vulnerability in Pluck CMS 4.6.1, allowing arbitrary file inclusion and command execution via log poisoning. The script injects a PHP payload into Apache logs and triggers it via the LFI vulnerability.
Description
Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the post parameter.
Exploits (1)
This exploit targets a Local File Inclusion (LFI) vulnerability in Pluck CMS 4.6.1, allowing arbitrary file inclusion and command execution via log poisoning. The script injects a PHP payload into Apache logs and triggers it via the LFI vulnerability.