Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2184. PoCs published by Lo$er.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Gravy Media Photo Host 1.0.8. The vulnerable code in forcedownload.php directly uses user-supplied input via $_GET['file'] without sanitization, allowing arbitrary file reads.
Description
Absolute path traversal vulnerability in forcedownload.php in Gravy Media Photo Host 1.0.8 allows remote attackers to read arbitrary files via an encoded "/" (slash) in the file parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Gravy Media Photo Host 1.0.8. The vulnerable code in forcedownload.php directly uses user-supplied input via $_GET['file'] without sanitization, allowing arbitrary file reads.