CVE-2008-6955
mxCamArchive 2.2 - Unauthenticated Exposure of Sensitive Information via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6955. PoCs published by ahmadbady.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in mxcamarchive 2.2 to achieve remote code execution by injecting PHP code into the web cam description field, which is then executed via a crafted HTTP request.
Description
mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini.
Exploits (1)
This exploit leverages a file inclusion vulnerability in mxcamarchive 2.2 to achieve remote code execution by injecting PHP code into the web cam description field, which is then executed via a crafted HTTP request.