Record summary

CVE-2014-8676 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBSO Planning 1.32 - Multiple VulnerabilitiesExploitDB exploitby Huy-Ngoc DAUNot analyzed1 file

linked to 5 vulnerabilities

ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMSimple Online Planning Tool <1.3.2 - Local File InclusionCVSS 5.3

SOPlanning <1.32 contain a directory traversal in the file_get_contents function via a .. (dot dot) in the fichier parameter.

Impact

An attacker can exploit this vulnerability to read sensitive files on the server.

Remediation

Upgrade Simple Online Planning Tool to version 1.3.2 or higher to fix the Local File Inclusion vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2014cvepacketstormedbseclistssoplanninglfixssvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*:*
Shodan: http.html:"soplanning"
FOFA: body="soplanning"

Source: ProjectDiscovery

References

5