Exploitation Summary
EIP tracks 2 public exploits for CVE-2013-4900. PoCs published by High-Tech Bridge, High-Tech Bridge SA.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Twilight CMS 0.4.2 by using encoded backslashes (%5c) to traverse directories and access sensitive files like win.ini or user list.dat. The PoC provides example HTTP GET requests to exploit the flaw.
Description
Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote attackers to read arbitrary files via a ..%5c (dot dot encoded backslash) in a GET request.
Exploits (2)
This exploit demonstrates a directory traversal vulnerability in Twilight CMS 0.4.2 by using encoded backslashes (%5c) to traverse directories and access sensitive files like win.ini or user list.dat. The PoC provides example HTTP GET requests to exploit the flaw.
The exploit demonstrates a path traversal vulnerability in DeWeS web server (CVE-2013-4900) by sending crafted HTTP GET requests with directory traversal sequences (e.g., '..%5c') to read arbitrary files, such as 'C:/windows/win.ini' or 'userlist.dat'. The PoC uses netcat to exploit the vulnerability.