CVE-2009-3664

Nullam Blog 0.1.2 - Path Traversal via p or s Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-3664. PoCs published by Salvatore Fresta.

AI-analyzed exploit summary This is a detailed technical writeup describing multiple vulnerabilities in Nullam Blog 0.1.2, including Local File Inclusion, File Disclosure, SQL Injection, and XSS. It provides code snippets, exploitation examples, and affected files.

Description

Multiple directory traversal vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to include or execute arbitrary files via a .. (dot dot) in the (1) p and (2) s parameters.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Salvatore Fresta · textwebappsphp
https://www.exploit-db.com/exploits/9625

This is a detailed technical writeup describing multiple vulnerabilities in Nullam Blog 0.1.2, including Local File Inclusion, File Disclosure, SQL Injection, and XSS. It provides code snippets, exploitation examples, and affected files.

Classification
Writeup 95%
Attack Type
Sqli | Xss | Info Leak | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Nullam Blog 0.1.2
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/53217
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/57919
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/506380/100/0/threaded
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9625
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36648

Scores

EPSS 0.0597
EPSS Percentile 92.4%

Details

CWE
CWE-22
Status published
Products (1)
nullam/nullam_blog 0.1.2
Published Oct 11, 2009
Tracked Since Feb 18, 2026