.. / CVE-2008-5587

Exploit for phpPgAdmin <=4.2.1 - Local File Inclusion (CVE-2008-5587)

Description:

phpPgAdmin 4.2.1 is vulnerable to local file inclusion in libraries/lib.inc.php when register globals is enabled. Remote attackers can read arbitrary files via a .. (dot dot) in the _language parameter to index.php.

Nuclei Template

View the template here CVE-2008-5587.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2008/CVE-2008-5587.yaml
Copy

References:

https://www.exploit-db.com/exploits/7363
http://securityreason.com/securityalert/4737
https://nvd.nist.gov/vuln/detail/CVE-2008-5587
http://lists.opensuse.org/opensuse-updates/2012-04/msg00033.html
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html