CVE-2010-2018
NUCLEILokomedia CMS 1.4.1 and 2.0 - Path Traversal via downlot.php file Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2018. PoCs published by vir0e5. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a local file disclosure vulnerability in Lokomedia CMS (sukaCMS) version 2.0. It allows an attacker to read arbitrary files by manipulating the 'file' parameter in the 'downlot.php' script.
Description
Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
Exploits (1)
This exploit demonstrates a local file disclosure vulnerability in Lokomedia CMS (sukaCMS) version 2.0. It allows an attacker to read arbitrary files by manipulating the 'file' parameter in the 'downlot.php' script.