CVE-2009-1318
Jamroom 3.1.2 3.2.3-3.2.6 4.0.2 - Remote File Inclusion via Directory Traversal in t Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1318. PoCs published by zxvf.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Jamroom versions 3.1.2 through 4.0.2. The vulnerability allows an attacker to include arbitrary local files by manipulating the 't' parameter in the URL with a null byte (%00) to bypass file extension restrictions.
Description
Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary files via directory traversal sequences in the t parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Jamroom versions 3.1.2 through 4.0.2. The vulnerability allows an attacker to include arbitrary local files by manipulating the 't' parameter in the URL with a null byte (%00) to bypass file extension restrictions.