CVE-2004-2750

JBrowser 1.0-2.1 - Path Traversal via Directory Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-2750. PoCs published by Himeur Nourredine.

AI-analyzed exploit summary The provided text describes a directory traversal vulnerability in JBrowser's 'browser.php' script, allowing remote attackers to access files outside the web server root due to insufficient input sanitization. The example URL demonstrates how an attacker can specify a path to traverse directories.

Description

Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary files via the directory parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Himeur Nourredine · textwebappsphp
https://www.exploit-db.com/exploits/23618

The provided text describes a directory traversal vulnerability in JBrowser's 'browser.php' script, allowing remote attackers to access files outside the web server root due to insufficient input sanitization. The example URL demonstrates how an attacker can specify a path to traverse directories.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: JBrowser (version not specified)
No auth needed
Prerequisites: Access to the 'browser.php' script on the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9535
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1008909

Scores

EPSS 0.0617
EPSS Percentile 92.6%

Details

CWE
CWE-22
Status published
Products (3)
jbrowser/jbrowser 1.0
jbrowser/jbrowser 2.0
jbrowser/jbrowser 2.1
Published Dec 31, 2004
Tracked Since Feb 18, 2026