Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-1768. PoCs published by Br0ly.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Rama Zaitan CMS versions 0.9.5 to 0.9.8. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the 'file' parameter in the download.php script.
Description
Directory traversal vulnerability in download.php in Rama Zaiten CMS 0.9.8 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in Rama Zaitan CMS versions 0.9.5 to 0.9.8. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the 'file' parameter in the download.php script.