CVE-2009-2109
FretsWeb 1.2 - Path Traversal via Language Parameter or Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2109. PoCs published by YEnH4ckEr.
AI-analyzed exploit summary This is a writeup detailing multiple local file inclusion (LFI) vulnerabilities in FretsWeb 1.2. It describes how to exploit the 'language' GET parameter and the 'fretsweb_language' cookie to include local files using null byte injection.
Description
Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) language parameter to charts.php and the (2) fretsweb_language cookie parameter to unspecified vectors, possibly related to admin/common.php.
Exploits (1)
This is a writeup detailing multiple local file inclusion (LFI) vulnerabilities in FretsWeb 1.2. It describes how to exploit the 'language' GET parameter and the 'fretsweb_language' cookie to include local files using null byte injection.