CVE-2014-6308

NUCLEI

OsClass < 3.4.2 - Path Traversal via File Parameter in oc-admin/index.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-6308. PoCs published by Netsparker. A Nuclei detection template is also available.

AI-analyzed exploit summary This is a vulnerability advisory detailing a Local File Inclusion (LFI) vulnerability in OsClass versions 3.4.1 and below. The advisory includes a proof-of-concept URL demonstrating the LFI vulnerability.

Description

Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a render action to oc-admin/index.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Netsparker · textwebappsphp
https://www.exploit-db.com/exploits/34763

This is a vulnerability advisory detailing a Local File Inclusion (LFI) vulnerability in OsClass versions 3.4.1 and below. The advisory includes a proof-of-concept URL demonstrating the LFI vulnerability.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: OsClass 3.4.1 and possibly below
No auth needed
Prerequisites: Access to the target OsClass installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Osclass Security Advisory 3.4.1 - Local File Inclusion
MEDIUMby daffainfo

Scores

EPSS 0.7413
EPSS Percentile 98.9%

Details

CWE
CWE-22
Status published
Products (2)
osclass/osclass 3.4.0
osclass/osclass < 3.4.1
Published Oct 20, 2014
Tracked Since Feb 18, 2026