CVE-2006-2280
openEngine <= 1.8 Beta 2 - Directory Traversal via Template Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2280. PoCs published by [email protected].
AI-analyzed exploit summary This exploit demonstrates an unauthorized access vulnerability in openEngine due to improper input sanitization. It allows an attacker to access sensitive files and administrative functions by manipulating the 'template' and other parameters.
Description
Directory traversal vulnerability in website.php in openEngine 1.8 Beta 2 and earlier allows remote attackers to list arbitrary directories and read arbitrary files via a .. (dot dot) in the template parameter.
Exploits (1)
This exploit demonstrates an unauthorized access vulnerability in openEngine due to improper input sanitization. It allows an attacker to access sensitive files and administrative functions by manipulating the 'template' and other parameters.