CVE-2014-3974
auracms < 3.0 - Cross-Site Scripting via filemanager.php viewdir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-3974. PoCs published by Mustafa ALTINKAYNAK.
AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in AuraCMS 3.0 via the 'viewdir' parameter in filemanager.php, which is directly echoed without proper sanitization. It also highlights an LFI vulnerability allowing directory listing.
Description
Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the viewdir parameter.
Exploits (1)
The exploit demonstrates a reflected XSS vulnerability in AuraCMS 3.0 via the 'viewdir' parameter in filemanager.php, which is directly echoed without proper sanitization. It also highlights an LFI vulnerability allowing directory listing.