Exploitation Summary
EIP tracks 2 public exploits for CVE-2009-2600. PoCs published by MrDoug.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Webboard <= v.2.90 beta, allowing remote file disclosure via manipulated 'topic' parameters in view.php. The vulnerability arises from insecure fopen() calls that do not sanitize user input, enabling path traversal attacks.
Description
Multiple directory traversal vulnerabilities in view.php in Webboard 2.90 beta and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the topic parameter.
Exploits (2)
This exploit demonstrates a directory traversal vulnerability in Webboard <= v.2.90 beta, allowing remote file disclosure via manipulated 'topic' parameters in view.php. The vulnerability arises from insecure fopen() calls that do not sanitize user input, enabling path traversal attacks.
This exploit demonstrates a directory traversal vulnerability in 212cafe WebBoard 2.90 beta, allowing attackers to read arbitrary files by manipulating the 'topic' parameter with '../' sequences.