CVE-2009-0766
Kipper 2.01 - Path Traversal and Arbitrary File Execution via Configfile Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0766.
AI-analyzed exploit summary The exploit demonstrates three vulnerabilities in Kipper 2.01: remote data reading via direct file access, local file inclusion via path traversal, and remote XSS via crafted input. The PoC provides direct URLs to exploit these issues.
Description
Directory traversal vulnerability in default.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the configfile parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The exploit demonstrates three vulnerabilities in Kipper 2.01: remote data reading via direct file access, local file inclusion via path traversal, and remote XSS via crafted input. The PoC provides direct URLs to exploit these issues.