CVE-2009-0286
OpenGoo 1.1 - Path Traversal via form_data[script_class] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0286. PoCs published by fuzion.
AI-analyzed exploit summary This exploit leverages a Local File Inclusion (LFI) vulnerability in OpenGoo 1.1 by manipulating the `form_data[script_class]` parameter to traverse directories and include arbitrary files, such as `/etc/passwd`. It requires specific PHP configurations (`magic_quotes_gpc = Off` and `register_globals = On`) to function.
Description
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the form_data[script_class] parameter.
Exploits (1)
This exploit leverages a Local File Inclusion (LFI) vulnerability in OpenGoo 1.1 by manipulating the `form_data[script_class]` parameter to traverse directories and include arbitrary files, such as `/etc/passwd`. It requires specific PHP configurations (`magic_quotes_gpc = Off` and `register_globals = On`) to function.