Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0423. PoCs published by Osirys.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Php Photo Album 0.8 BETA. The vulnerability arises due to insufficient input validation in the 'preview' parameter, allowing directory traversal attacks to include arbitrary local files.
Description
Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the preview parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Php Photo Album 0.8 BETA. The vulnerability arises due to insufficient input validation in the 'preview' parameter, allowing directory traversal attacks to include arbitrary local files.