Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-3508. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates Local File Inclusion (LFI) vulnerabilities in MUJE CMS 1.0.4.34. It provides PoC URLs to read arbitrary files (e.g., boot.ini) via path traversal, with some vectors requiring admin access.
Description
Multiple directory traversal vulnerabilities in MUJE CMS 1.0.4.34 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) _class parameter to admin.php and the (2) url parameter to install/install.php; and allow remote authenticated administrators to read arbitrary files via a .. (dot dot) in the (3) _htmlfile parameter to admin.php.
Exploits (1)
This exploit demonstrates Local File Inclusion (LFI) vulnerabilities in MUJE CMS 1.0.4.34. It provides PoC URLs to read arbitrary files (e.g., boot.ini) via path traversal, with some vectors requiring admin access.