CVE-2012-5192

bitweaver < 2.8.1 - Path Traversal via overlay_type Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2012-5192. PoCs published by David Aaron, Jonathan Claudius, sinn3r, including Metasploit module auxiliary/scanner/http/bitweaver_overlay_type_traversal.

AI-analyzed exploit summary The document details multiple vulnerabilities in Bitweaver, including a Local File Inclusion (LFI) vulnerability in the 'overlay_type' parameter and several Cross-Site Scripting (XSS) vulnerabilities in various endpoints. It provides technical details, proof-of-concept requests, and remediation steps.

Description

Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files via "''%2F" (dot dot encoded slash) sequences in the overlay_type parameter.

Exploits (2)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/22216

The document details multiple vulnerabilities in Bitweaver, including a Local File Inclusion (LFI) vulnerability in the 'overlay_type' parameter and several Cross-Site Scripting (XSS) vulnerabilities in various endpoints. It provides technical details, proof-of-concept requests, and remediation steps.

Classification
Writeup 100%
Attack Type
Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Bitweaver 2.8.1 and earlier
No auth needed
Prerequisites: Access to the vulnerable Bitweaver instance
devstral-2 · analyzed Feb 19, 2026 Full analysis →
metasploit WORKING POC
by David Aaron, Jonathan Claudius, sinn3r · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/bitweaver_overlay_type_traversal.rb

This Metasploit module exploits a directory traversal vulnerability in Bitweaver via the 'overlay_type' parameter in view_overlay.php, allowing arbitrary file reads. It sends a crafted GET request with traversal sequences to read files outside the web root.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Bitweaver (versions affected by CVE-2012-5192)
No auth needed
Prerequisites: Network access to the target web application · Bitweaver installation with vulnerable view_overlay.php
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

EPSS 0.5248
EPSS Percentile 98.8%

Details

CWE
CWE-22
Status published
Products (11)
bitweaver/bitweaver 1.1
bitweaver/bitweaver 1.1.1_beta
bitweaver/bitweaver 1.2.1
bitweaver/bitweaver 1.3
bitweaver/bitweaver 1.3.1
bitweaver/bitweaver 2.0.0
bitweaver/bitweaver 2.0.2
bitweaver/bitweaver 2.5
bitweaver/bitweaver 2.6
bitweaver/bitweaver 2.7
... and 1 more
Published Jan 28, 2014
Tracked Since Feb 18, 2026