Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2166. PoCs published by Nico Leidecker.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in OCS Inventory NG 1.02 (Unix) via the cvs.php script, allowing unauthenticated attackers to read arbitrary files from the hosting system by manipulating the 'log' parameter.
Description
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in OCS Inventory NG 1.02 (Unix) via the cvs.php script, allowing unauthenticated attackers to read arbitrary files from the hosting system by manipulating the 'log' parameter.