Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-1951. PoCs published by eidelweiss.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in 60cycleCMS v2.5.2 due to improper handling of the DOCUMENT_ROOT parameter. The PoC shows how an attacker can manipulate the parameter to include arbitrary files.
Description
Multiple directory traversal vulnerabilities in 60cycleCMS allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the DOCUMENT_ROOT parameter to (1) news.php, (2) submitComment.php, and (3) sqlConnect.php.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in 60cycleCMS v2.5.2 due to improper handling of the DOCUMENT_ROOT parameter. The PoC shows how an attacker can manipulate the parameter to include arbitrary files.