CVE-2008-2969
Academic Web Tools <= 1.4.2.8 - Path Traversal via dfile Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2969.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Academic Web Tools CMS, including directory traversal, SQL injection, XSS, and session fixation. It provides functional PoC examples for each vulnerability, such as traversal via 'dfile' parameter and SQLi via 'book_id'.
Description
Directory traversal vulnerability in download.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the dfile parameter.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Academic Web Tools CMS, including directory traversal, SQL injection, XSS, and session fixation. It provides functional PoC examples for each vulnerability, such as traversal via 'dfile' parameter and SQLi via 'book_id'.