CVE-2014-100029
Ganesha Digital Library 4.2 - Path Traversal via Newlang or Newtheme Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-100029.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in GDL 4.2, including directory traversal via 'newlang' and 'newtheme' parameters, SQL injection in 'download.php', blind SQL injection in 'gdl.php', and XSS in the search module. It provides specific URLs and code snippets to exploit these flaws.
Description
Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) newlang or (2) newtheme parameter.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in GDL 4.2, including directory traversal via 'newlang' and 'newtheme' parameters, SQL injection in 'download.php', blind SQL injection in 'gdl.php', and XSS in the search module. It provides specific URLs and code snippets to exploit these flaws.