CVE-2010-2341
ezpx_photoblog 1.2 beta - Remote Code Execution via tpl_base_dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2341. PoCs published by sh00t0ut.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in EZPX photoblog 1.2 beta by manipulating the 'tpl_base_dir' parameter to include an external script. The attack leverages improper input validation to execute arbitrary code.
Description
PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the tpl_base_dir parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in EZPX photoblog 1.2 beta by manipulating the 'tpl_base_dir' parameter to include an external script. The attack leverages improper input validation to execute arbitrary code.