CVE-2009-2922
Pixaria Gallery 2.0.0-2.3.5 - Path Traversal via Base64-Encoded File Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2922. PoCs published by Qabandi.
AI-analyzed exploit summary This exploit targets a file disclosure vulnerability in Pixaria Gallery 2.3.5 by sending a crafted HTTP GET request with a base64-encoded file path to retrieve arbitrary files from the server. The script constructs a raw HTTP request and reads the response to display the file contents.
Description
Absolute path traversal vulnerability in pixaria.image.php in Pixaria Gallery 2.0.0 through 2.3.5 allows remote attackers to read arbitrary files via a base64-encoded file parameter.
Exploits (1)
This exploit targets a file disclosure vulnerability in Pixaria Gallery 2.3.5 by sending a crafted HTTP GET request with a base64-encoded file path to retrieve arbitrary files from the server. The script constructs a raw HTTP request and reads the response to display the file contents.