Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-1770. PoCs published by ahmadbady.
AI-analyzed exploit summary The exploit demonstrates a Local File Inclusion (LFI) vulnerability in Flyspeck CMS 6.8, allowing arbitrary file inclusion via the 'lang' parameter. It also includes a form to change the admin password and add a new admin user by exploiting an insecure direct object reference.
Description
Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
Exploits (1)
The exploit demonstrates a Local File Inclusion (LFI) vulnerability in Flyspeck CMS 6.8, allowing arbitrary file inclusion via the 'lang' parameter. It also includes a form to change the admin password and add a new admin user by exploiting an insecure direct object reference.