Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0448. PoCs published by ahmadbady.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Syntax Desktop 2-7 via the 'preview.php' script, allowing arbitrary file inclusion through the 'synTarget' parameter. The null byte (%00) is used to bypass file extension restrictions.
Description
Directory traversal vulnerability in admin/modules/aa/preview.php in Syntax Desktop 2.7 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the synTarget parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Syntax Desktop 2-7 via the 'preview.php' script, allowing arbitrary file inclusion through the 'synTarget' parameter. The null byte (%00) is used to bypass file extension restrictions.