Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-4978. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates Arbitrary File Download (AFD) and Remote File Inclusion (RFI) vulnerabilities in MyBackup 1.4.0. The AFD allows reading local files via path traversal, while the RFI requires authentication and can execute remote scripts.
Description
Directory traversal vulnerability in down.php in MyBackup 1.4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
Exploits (1)
This exploit demonstrates Arbitrary File Download (AFD) and Remote File Inclusion (RFI) vulnerabilities in MyBackup 1.4.0. The AFD allows reading local files via path traversal, while the RFI requires authentication and can execute remote scripts.