CVE-2009-3825
GenCMS 2006 - Path Traversal via 'p' Parameter in show.php and 'Template' Parameter in admin/pages/SiteNew.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3825. PoCs published by eLwaux.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in GenCMS. It leverages improper input validation in the 'p' parameter of /show.php and the 'Template' parameter in /admin/pages/SiteNew.php to include arbitrary files via directory traversal and null byte injection.
Description
Multiple directory traversal vulnerabilities in GenCMS 2006 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) p parameter to show.php and the (2) Template parameter to admin/pages/SiteNew.php.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in GenCMS. It leverages improper input validation in the 'p' parameter of /show.php and the 'Template' parameter in /admin/pages/SiteNew.php to include arbitrary files via directory traversal and null byte injection.