CVE-2008-1231
JSPWiki 2.4.104 and 2.5.139 - Path Traversal via Edit.jsp Editor Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1231. PoCs published by BugSec LTD.
AI-analyzed exploit summary The document describes multiple vulnerabilities in JSPWiki, including a local .jsp file inclusion vulnerability and a cross-site scripting (XSS) vulnerability. It provides technical details on how these vulnerabilities can be exploited to disclose sensitive information or execute arbitrary script code.
Description
Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and execute arbitrary local .jsp files, and obtain sensitive information, via a .. (dot dot) in the editor parameter.
Exploits (1)
The document describes multiple vulnerabilities in JSPWiki, including a local .jsp file inclusion vulnerability and a cross-site scripting (XSS) vulnerability. It provides technical details on how these vulnerabilities can be exploited to disclose sensitive information or execute arbitrary script code.