Exploitation Summary
EIP tracks 1 public exploit for CVE-2011-1715. PoCs published by AutoSec Tools.
AI-analyzed exploit summary The exploit demonstrates a Local File Inclusion (LFI) vulnerability in eyeOS 2.3, allowing arbitrary file inclusion via path traversal. It also includes a reflected XSS vulnerability in the same software.
Description
Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows remote attackers to read arbitrary files via ..%2f (encoded dot dot) sequences in the file parameter.
Exploits (1)
The exploit demonstrates a Local File Inclusion (LFI) vulnerability in eyeOS 2.3, allowing arbitrary file inclusion via path traversal. It also includes a reflected XSS vulnerability in the same software.