Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-1790. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Webgrind 1.0, where the 'file' parameter in index.php is not properly sanitized, allowing directory traversal and inclusion of arbitrary local files.
Description
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parameter to index.php.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Webgrind 1.0, where the 'file' parameter in index.php is not properly sanitized, allowing directory traversal and inclusion of arbitrary local files.