Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-1407. PoCs published by Kacper.
AI-analyzed exploit summary This exploit demonstrates a local file inclusion vulnerability in NotFTP 1.3.1 due to improper input validation in the 'newlang' parameter. The PoC shows how an attacker can traverse directories to read arbitrary files like '/etc/passwd'.
Description
Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a certain languages[][file] parameter.
Exploits (1)
This exploit demonstrates a local file inclusion vulnerability in NotFTP 1.3.1 due to improper input validation in the 'newlang' parameter. The PoC shows how an attacker can traverse directories to read arbitrary files like '/etc/passwd'.