CVE-2008-0473
Web Wiz Rich Text Editor 4.0 - Unauthenticated Arbitrary File Upload via RTE_popup_save_file.asp
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0473. PoCs published by BugReport.IR.
AI-analyzed exploit summary The advisory details a directory traversal vulnerability in Web Wiz Rich Text Editor 4.0, allowing unauthenticated attackers to list directories and create HTML/HTM files on the server via the 'FolderName' parameter in 'RTE_file_browser.asp'. It includes proof-of-concept URLs and mitigation steps.
Description
RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors.
Exploits (1)
The advisory details a directory traversal vulnerability in Web Wiz Rich Text Editor 4.0, allowing unauthenticated attackers to list directories and create HTML/HTM files on the server via the 'FolderName' parameter in 'RTE_file_browser.asp'. It includes proof-of-concept URLs and mitigation steps.