CVE-2010-4401
DynPG CMS 4.2.0 - Sensitive Information Exposure via languages.inc.php Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-4401. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates a Local File Inclusion (LFI) vulnerability in DynPG 4.2.0 via the CHG_DYNPG_SET_LANGUAGE parameter, along with path disclosure and SQL injection vulnerabilities. The PoC provides forms to exploit these issues, requiring authentication for some attacks.
Description
languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
Exploits (1)
The exploit demonstrates a Local File Inclusion (LFI) vulnerability in DynPG 4.2.0 via the CHG_DYNPG_SET_LANGUAGE parameter, along with path disclosure and SQL injection vulnerabilities. The PoC provides forms to exploit these issues, requiring authentication for some attacks.