Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-4798. PoCs published by ZonTa.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in OrangeHRM 2.6.0.1 by manipulating the 'uri' parameter in the URL to include local files. The PoC provides a direct URL example to exploit the vulnerability.
Description
Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the uri parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in OrangeHRM 2.6.0.1 by manipulating the 'uri' parameter in the URL to include local files. The PoC provides a direct URL example to exploit the vulnerability.