Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-1003. PoCs published by 7Safe.
AI-analyzed exploit summary This exploit demonstrates a local file inclusion vulnerability in eFront due to improper input sanitization. It allows an attacker to read arbitrary files or execute local scripts by manipulating the 'langname' parameter.
Description
Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langname parameter.
Exploits (1)
This exploit demonstrates a local file inclusion vulnerability in eFront due to improper input sanitization. It allows an attacker to read arbitrary files or execute local scripts by manipulating the 'langname' parameter.