Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-1301. PoCs published by nnposter.
AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in Alkacon OpenCms by manipulating the 'filePath.0' parameter to read arbitrary files (e.g., /etc/passwd). The attack leverages insufficient input validation in the logfileViewSettings.jsp endpoint.
Description
Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 parameter.
Exploits (1)
This exploit demonstrates an information disclosure vulnerability in Alkacon OpenCms by manipulating the 'filePath.0' parameter to read arbitrary files (e.g., /etc/passwd). The attack leverages insufficient input validation in the logfileViewSettings.jsp endpoint.