Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-5242. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Banana Dance B.2.6, including PHP file inclusion, improper access control, and SQL injection. It provides proof-of-concept examples for each vulnerability, showcasing how arbitrary files can be included, sensitive database information can be accessed, and SQL queries can be manipulated.
Description
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Banana Dance B.2.6, including PHP file inclusion, improper access control, and SQL injection. It provides proof-of-concept examples for each vulnerability, showcasing how arbitrary files can be included, sensitive database information can be accessed, and SQL queries can be manipulated.