CVE-2007-6651
bitweaver - Path Traversal via wiki/edit.php suck_url Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6651. PoCs published by BugReport.IR.
AI-analyzed exploit summary The document describes two vulnerabilities in Bitweaver R2 CMS: arbitrary file upload due to insufficient content-type validation and source code disclosure via directory traversal in the 'suck_url' parameter. No executable exploit code is provided.
Description
Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script source code) via a .. (dot dot) in the suck_url parameter.
Exploits (1)
The document describes two vulnerabilities in Bitweaver R2 CMS: arbitrary file upload due to insufficient content-type validation and source code disclosure via directory traversal in the 'suck_url' parameter. No executable exploit code is provided.