Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-4986. PoCs published by Angela Chang.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in In-Portal 4.3.1 by manipulating the 'env' parameter to include arbitrary files via directory traversal sequences. The PoC includes a demo URL showing how to read '/etc/passwd'.
Description
Directory traversal vulnerability in index.php in In-Portal 4.3.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the env parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in In-Portal 4.3.1 by manipulating the 'env' parameter to include arbitrary files via directory traversal sequences. The PoC includes a demo URL showing how to read '/etc/passwd'.