CVE-2014-4306

WebTitan < 4.01 - Path Traversal via Logfile Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-4306.

AI-analyzed exploit summary This is a detailed security advisory from SEC Consult Vulnerability Lab describing multiple critical vulnerabilities in WebTitan 4.01 (Build 68), including SQL injection, remote command execution, path traversal, and unprotected access. It provides technical details, affected parameters, and proof-of-concept examples for each vulnerability.

Description

Directory traversal vulnerability in logs-x.php in WebTitan before 4.04 allows remote attackers to read arbitrary files via a .. (dot dot) in the logfile parameter in a download action.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/33699

This is a detailed security advisory from SEC Consult Vulnerability Lab describing multiple critical vulnerabilities in WebTitan 4.01 (Build 68), including SQL injection, remote command execution, path traversal, and unprotected access. It provides technical details, affected parameters, and proof-of-concept examples for each vulnerability.

Classification
Writeup 100%
Attack Type
Rce | Sqli | Info Leak | Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: WebTitan 4.01 (Build 68)
No auth needed
Prerequisites: Network access to the WebTitan web interface
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

EPSS 0.0762
EPSS Percentile 93.8%

Details

CWE
CWE-22
Status published
Products (1)
webtitan/webtitan < 4.01
Published Jun 18, 2014
Tracked Since Feb 18, 2026