CVE-2014-10010

PHPJabbers Appointment Scheduler 2.0 - Path Traversal via Backup Controller ID Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-10010. PoCs published by HackXBack.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Appointment Scheduler V2.0, including XSS, CSRF, and local file disclosure. It provides functional PoC code for each vulnerability, leveraging HTML forms and path traversal techniques.

Description

Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownload action to the pjBackup controller.

Exploits (1)

exploitdb WORKING POC
by HackXBack · textwebappsphp
https://www.exploit-db.com/exploits/30911

The exploit demonstrates multiple vulnerabilities in Appointment Scheduler V2.0, including XSS, CSRF, and local file disclosure. It provides functional PoC code for each vulnerability, leveraging HTML forms and path traversal techniques.

Classification
Working Poc 90%
Attack Type
Xss | Info Leak | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Appointment Scheduler V2.0
No auth needed
Prerequisites: Victim interaction for XSS/CSRF · Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/30911
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90421

Scores

EPSS 0.0765
EPSS Percentile 93.8%

Details

CWE
CWE-22
Status published
Products (1)
phpjabbers/appointment_scheduler 2.0
Published Jan 13, 2015
Tracked Since Feb 18, 2026