CVE-2009-1456
Malleo 1.2.3 - Authenticated Path Traversal via Module Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1456. PoCs published by Drosophila.
AI-analyzed exploit summary The exploit describes a local file inclusion (LFI) vulnerability in Malleo 1.2.3 due to improper input sanitization. An attacker can traverse directories and include arbitrary local files via the 'module' parameter in admin.php.
Description
Directory traversal vulnerability in admin.php in Malleo 1.2.3 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the module parameter.
Exploits (1)
The exploit describes a local file inclusion (LFI) vulnerability in Malleo 1.2.3 due to improper input sanitization. An attacker can traverse directories and include arbitrary local files via the 'module' parameter in admin.php.