CVE-2008-1231

JSPWiki 2.4.104 and 2.5.139 - Path Traversal via Edit.jsp Editor Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-1231. PoCs published by BugSec LTD.

AI-analyzed exploit summary The document describes multiple vulnerabilities in JSPWiki, including a local .jsp file inclusion vulnerability and a cross-site scripting (XSS) vulnerability. It provides technical details on how these vulnerabilities can be exploited to disclose sensitive information or execute arbitrary script code.

Description

Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and execute arbitrary local .jsp files, and obtain sensitive information, via a .. (dot dot) in the editor parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by BugSec LTD · textwebappsjsp
https://www.exploit-db.com/exploits/5112

The document describes multiple vulnerabilities in JSPWiki, including a local .jsp file inclusion vulnerability and a cross-site scripting (XSS) vulnerability. It provides technical details on how these vulnerabilities can be exploited to disclose sensitive information or execute arbitrary script code.

Classification
Writeup 90%
Attack Type
Info Leak | Xss
Complexity
Trivial
Reliability
Reliable
Target: JSPWiki v2.4.104, JSPWiki v2.5.139
No auth needed
Prerequisites: Access to the target JSPWiki instance · Knowledge of existing pages on the server
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=120300554011544&w=2
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28969
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27785
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/40508
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5112

Scores

EPSS 0.0761
EPSS Percentile 93.8%

Details

CWE
CWE-22
Status published
Products (3)
jspwiki/jspwiki 2.4.104
jspwiki/jspwiki 2.5.139
jspwiki/jspwiki 2.5.139_beta
Published Mar 10, 2008
Tracked Since Feb 18, 2026