CVE-2009-1748
Catviz 0.4.0 Beta 1 - Path Traversal via webpages_form or userman_form Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1748. PoCs published by ByALBAYX.
AI-analyzed exploit summary This is a writeup detailing Local File Inclusion (LFI) and Cross-Site Scripting (XSS) vulnerabilities in Catviz 0.4.0 Beta 1. It provides example URLs to exploit these vulnerabilities but does not include functional exploit code.
Description
Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) webpages_form or (2) userman_form parameter.
Exploits (1)
This is a writeup detailing Local File Inclusion (LFI) and Cross-Site Scripting (XSS) vulnerabilities in Catviz 0.4.0 Beta 1. It provides example URLs to exploit these vulnerabilities but does not include functional exploit code.