CVE-2009-2923
BitmixSoft PHP-Lance 1.52 - Path Traversal via Language or Search Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2923. PoCs published by jetli007.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in PHP-Lance v1.52. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the 'language' or 'in' parameters in specific PHP scripts.
Description
Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to show.php and (2) in parameter to advanced_search.php.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in PHP-Lance v1.52. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the 'language' or 'in' parameters in specific PHP scripts.