CVE-2001-1525
easyNews 1.5 and earlier - Directory Traversal via cid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2001-1525. PoCs published by markus arndt.
AI-analyzed exploit summary This exploit leverages a path traversal vulnerability in EasyNews to modify the Newsdatabase by crafting a malicious web request. It allows an attacker to post unmoderated comments or alter template information.
Description
Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly other files via a ".." in the cid parameter.
Exploits (1)
This exploit leverages a path traversal vulnerability in EasyNews to modify the Newsdatabase by crafting a malicious web request. It allows an attacker to post unmoderated comments or alter template information.