CVE-2013-3739
EXPLOITEDNetwork Weathermap < 0.97c - Path Traversal via Mapname Parameter
Title source: llmExploitation Summary
CVE-2013-3739 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Anthony Dubuissez.
AI-analyzed exploit summary The advisory describes a Local File Inclusion (LFI) vulnerability in Network Weathermap <= 0.97C due to improper sanitization of the 'mapname' parameter in editor.php. The PoC demonstrates LFI via a crafted URL to read arbitrary files, bypassing the '.config' restriction.
Description
Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the mapname parameter in a show_config action.
Exploits (1)
The advisory describes a Local File Inclusion (LFI) vulnerability in Network Weathermap <= 0.97C due to improper sanitization of the 'mapname' parameter in editor.php. The PoC demonstrates LFI via a crafted URL to read arbitrary files, bypassing the '.config' restriction.