CVE-2008-0479
Web Wiz NewsPad 1.02 - Path Traversal via RTE_file_browser.asp Sub Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0479. PoCs published by BugReport.IR.
AI-analyzed exploit summary The exploit describes a directory traversal vulnerability in Web Wiz NewsPad 1.02 due to improper sanitization of the FolderName parameter in RTE_file_browser.asp. It includes a PoC URL and a fast solution to mitigate the issue.
Description
Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter.
Exploits (1)
The exploit describes a directory traversal vulnerability in Web Wiz NewsPad 1.02 due to improper sanitization of the FolderName parameter in RTE_file_browser.asp. It includes a PoC URL and a fast solution to mitigate the issue.