Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-4801. PoCs published by John Leitch.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in BaconMap 1.0 by manipulating the 'filepath' parameter in 'updatelist.php' to include arbitrary files. The PoC shows how an attacker can access sensitive files like 'settings.php' by traversing directories.
Description
Directory traversal vulnerability in admin/updatelist.php in BaconMap 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filepath parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in BaconMap 1.0 by manipulating the 'filepath' parameter in 'updatelist.php' to include arbitrary files. The PoC shows how an attacker can access sensitive files like 'settings.php' by traversing directories.