CVE-2008-7176
Facil CMS 0.1RC - Path Traversal via change_lang or modload Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-7176. PoCs published by eidelweiss, CWH Underground.
AI-analyzed exploit summary This exploit demonstrates Local File Inclusion (LFI) and Remote File Inclusion (RFI) vulnerabilities in Facil-CMS 0.1RC2. The PoC shows how arbitrary files can be included via path traversal in the `modload` and `getSiteIndex` parameters.
Description
Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) change_lang parameter to index.php or (2) modload parameter to modules.php.
Exploits (2)
This exploit demonstrates Local File Inclusion (LFI) and Remote File Inclusion (RFI) vulnerabilities in Facil-CMS 0.1RC2. The PoC shows how arbitrary files can be included via path traversal in the `modload` and `getSiteIndex` parameters.
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Facil-CMS 0.1RC. It allows an attacker to read arbitrary files on the server by manipulating the 'change_lang' or 'modload' parameters in the URL.