Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2338. PoCs published by ahmadbady.
AI-analyzed exploit summary This exploit demonstrates a local file inclusion vulnerability in FreeWebshop.org 2.2.9_R2. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the 'lang_file' parameter in the 'startmodules.inc.php' script.
Description
Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_file parameter.
Exploits (1)
This exploit demonstrates a local file inclusion vulnerability in FreeWebshop.org 2.2.9_R2. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the 'lang_file' parameter in the 'startmodules.inc.php' script.