Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-1625. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Thickbox Gallery v2. The PoC shows how an attacker can traverse directories to access arbitrary files on the server by manipulating the 'ln' parameter in the URL.
Description
Directory traversal vulnerability in index.php in Thickbox Gallery 2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ln parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Thickbox Gallery v2. The PoC shows how an attacker can traverse directories to access arbitrary files on the server by manipulating the 'ln' parameter in the URL.