CVE-2010-2336
Yamamah Photo Gallery 1.00 - Unauthenticated Source Code Disclosure via Download Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2336. PoCs published by anT!-Tr0J4n.
AI-analyzed exploit summary The exploit demonstrates SQL injection and local file inclusion vulnerabilities in Yamamah CMS version 1.00. It includes proof-of-concept URLs for blind SQL injection and arbitrary file disclosure via the 'download' parameter.
Description
index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the download parameter.
Exploits (1)
The exploit demonstrates SQL injection and local file inclusion vulnerabilities in Yamamah CMS version 1.00. It includes proof-of-concept URLs for blind SQL injection and arbitrary file disclosure via the 'download' parameter.