CVE-2009-1488
FunGamez RC1 - Remote File Inclusion via Module Parameter Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1488. PoCs published by YEnH4ckEr.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in the login form and insecure cookie handling, as well as a local file inclusion (LFI) vulnerability in the admin module. The PoC provides clear steps to exploit these vulnerabilities in FunGamez RC-1.
Description
Directory traversal vulnerability in admin/load.php in FunGamez RC1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter to index.php.
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in the login form and insecure cookie handling, as well as a local file inclusion (LFI) vulnerability in the admin module. The PoC provides clear steps to exploit these vulnerabilities in FunGamez RC-1.