Exploitation Summary
EIP tracks 2 public exploits for CVE-2009-0291. PoCs published by Charlie Briggs, Sarid Harper.
AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in OpenX (formerly Openads) by injecting a null byte into the MAX_type parameter to bypass file inclusion restrictions and read arbitrary files. The PoC demonstrates reading /etc/passwd via path traversal.
Description
Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the MAX_type parameter.
Exploits (2)
This exploit leverages a directory traversal vulnerability in OpenX (formerly Openads) by injecting a null byte into the MAX_type parameter to bypass file inclusion restrictions and read arbitrary files. The PoC demonstrates reading /etc/passwd via path traversal.
This exploit demonstrates a local file inclusion (LFI) vulnerability in OpenX 2.6.3 by manipulating the 'MAX_type' parameter to traverse directories and include arbitrary files, such as '/etc/passwd'.