CVE-2011-2744
NUCLEIChyrp < 2.1 - Remote File Inclusion via Action Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-2744. PoCs published by Wireghoul. A Nuclei detection template is also available.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in Chyrp 2.1, including XSS, LFI, arbitrary file upload, and directory traversal. It includes a PoC URL for directory traversal to access /etc/passwd.
Description
Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the action parameter to the default URI.
Exploits (1)
The provided text describes multiple vulnerabilities in Chyrp 2.1, including XSS, LFI, arbitrary file upload, and directory traversal. It includes a PoC URL for directory traversal to access /etc/passwd.