Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2180. PoCs published by Qabandi.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in pc4 Uploader <= 10.0, allowing remote file disclosure via unsanitized user input in the 'file' parameter. The PoC includes example URLs to exploit the flaw and retrieve sensitive files like config.php or /etc/passwd.
Description
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the file parameter.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in pc4 Uploader <= 10.0, allowing remote file disclosure via unsanitized user input in the 'file' parameter. The PoC includes example URLs to exploit the flaw and retrieve sensitive files like config.php or /etc/passwd.