packetstormsecurity.com
http://packetstormsecurity.com/files/132654/Simple-Online-Planning-Tool-1.3.2-XSS-SQL-Injection-Traversal.html CVE-2014-8676
MEDIUMNuclei
SO Planning 1.32 - Multiple Vulnerabilities
Record summary
CVE-2014-8676 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.
Description source: CVE List
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBSO Planning 1.32 - Multiple VulnerabilitiesExploitDB exploitby Huy-Ngoc DAUNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMSimple Online Planning Tool <1.3.2 - Local File InclusionCVSS 5.3
SOPlanning <1.32 contain a directory traversal in the file_get_contents function via a .. (dot dot) in the fichier parameter.
Impact
An attacker can exploit this vulnerability to read sensitive files on the server.
Remediation
Upgrade Simple Online Planning Tool to version 1.3.2 or higher to fix the Local File Inclusion vulnerability.
WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2014cvepacketstormedbseclistssoplanninglfixssvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*:*
Shodan: http.html:"soplanning"
FOFA: body="soplanning"
https://packetstormsecurity.com/files/132654/Simple-Online-Planning-Tool-1.3.2-XSS-SQL-Injection-Traversal.html https://www.exploit-db.com/exploits/37604/ http://seclists.org/fulldisclosure/2015/Jul/44 https://nvd.nist.gov/vuln/detail/CVE-2014-8676 http://packetstormsecurity.com/files/132654/Simple-Online-Planning-Tool-1.3.2-XSS-SQL-Injection-Traversal.html
Source: ProjectDiscovery
References
520150708 SOPlanning - Simple Online Planning Tool multiple vulnerabilitiesmailing list
http://seclists.org/fulldisclosure/2015/Jul/44 75726vdb entry
http://www.securityfocus.com/bid/75726 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-8676 37604exploit
https://www.exploit-db.com/exploits/37604