CVE-2014-3975
AuraCMS 3.0 - Path Traversal via filemanager.php viewdir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-3975. PoCs published by Mustafa ALTINKAYNAK.
AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in AuraCMS 3.0 via the 'viewdir' parameter in filemanager.php, which is directly echoed without proper sanitization. It also highlights an LFI vulnerability allowing directory listing.
Description
Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in the viewdir parameter.
Exploits (1)
The exploit demonstrates a reflected XSS vulnerability in AuraCMS 3.0 via the 'viewdir' parameter in filemanager.php, which is directly echoed without proper sanitization. It also highlights an LFI vulnerability allowing directory listing.