CVE-2008-1230
JSPWiki 2.4.104 and 2.5.139 - Unauthenticated Arbitrary File Upload and Remote Code Execution via JSP File Attachment
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1230. PoCs published by BugSec LTD.
AI-analyzed exploit summary The document describes multiple vulnerabilities in JSPWiki, including a local .jsp file inclusion vulnerability and a cross-site scripting (XSS) vulnerability. It provides technical details on how these vulnerabilities can be exploited to disclose sensitive information or execute arbitrary script code.
Description
Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbitrary .jsp files via an unspecified manipulation that attaches a .jsp file to an "entry page."
Exploits (1)
The document describes multiple vulnerabilities in JSPWiki, including a local .jsp file inclusion vulnerability and a cross-site scripting (XSS) vulnerability. It provides technical details on how these vulnerabilities can be exploited to disclose sensitive information or execute arbitrary script code.