CVE-2008-2878
Academic Web Tools < 1.4.2.8 - Open Redirect via rss_getfile.php file Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2878.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Academic Web Tools CMS, including directory traversal, SQL injection, XSS, and session fixation. It provides functional PoC URLs and payloads for each vulnerability.
Description
Open redirect vulnerability in rss_getfile.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the file parameter.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in Academic Web Tools CMS, including directory traversal, SQL injection, XSS, and session fixation. It provides functional PoC URLs and payloads for each vulnerability.