CVE-2009-0722
Potato News 1.0.0 - Unauthenticated Path Traversal via User Cookie Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0722. PoCs published by x0r.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Potato News 1.0.0 via cookie manipulation. The attacker sets a malicious cookie to include arbitrary files (e.g., /etc/passwd) due to improper input validation in admin.php.
Description
Directory traversal vulnerability in admin.php in Potato News 1.0.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the user cookie parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Potato News 1.0.0 via cookie manipulation. The attacker sets a malicious cookie to include arbitrary files (e.g., /etc/passwd) due to improper input validation in admin.php.