Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-1309. PoCs published by eidelweiss.
AI-analyzed exploit summary The exploit demonstrates a Local File Inclusion (LFI) vulnerability in Pepsi CMS (Irmin CMS) version pepsi-0.6-BETA2. It leverages improper file path handling in `index.php` and `includes/template-loader.php` to include arbitrary files via the `w` and `_Root_Path` parameters.
Description
Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary files via a .. (dot dot) in the w parameter to index.php.
Exploits (1)
The exploit demonstrates a Local File Inclusion (LFI) vulnerability in Pepsi CMS (Irmin CMS) version pepsi-0.6-BETA2. It leverages improper file path handling in `index.php` and `includes/template-loader.php` to include arbitrary files via the `w` and `_Root_Path` parameters.