Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3708. PoCs published by Don.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in dotCMS, allowing unauthorized access to sensitive files like /etc/passwd by manipulating the 'id' parameter with traversal sequences. The PoC provides clear examples of exploitable URLs.
Description
Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) news/index.dot and (2) getting_started/macros/macros_detail.dot.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in dotCMS, allowing unauthorized access to sensitive files like /etc/passwd by manipulating the 'id' parameter with traversal sequences. The PoC provides clear examples of exploitable URLs.