CVE-2009-1445
WebPortal CMS 0.8-beta - Path Traversal and Arbitrary File Read via lang Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1445. PoCs published by ahmadbady.
AI-analyzed exploit summary This exploit demonstrates a local file inclusion (LFI) vulnerability in WebPortal 0.8-beta, allowing an attacker to read local files or include remote files via null byte injection and path manipulation.
Description
Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary files via directory traversal sequences in the lang parameter to libraries/helpdocs/help.php and (2) include and execute arbitrary local files via directory traversal sequences in the error parameter to index.php.
Exploits (1)
This exploit demonstrates a local file inclusion (LFI) vulnerability in WebPortal 0.8-beta, allowing an attacker to read local files or include remote files via null byte injection and path manipulation.