CVE-2014-8676
MEDIUM NUCLEIsoplanning < 1.32 - Path Traversal via URL Path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-8676. PoCs published by Huy-Ngoc DAU. A Nuclei detection template is also available.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in SOPlanning 1.32 and prior, including SQL injection, XSS, path traversal, authentication hash disclosure, and PHP code injection during installation. It provides detailed proof-of-concept examples for each vulnerability.
Description
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in SOPlanning 1.32 and prior, including SQL injection, XSS, path traversal, authentication hash disclosure, and PHP code injection during installation. It provides detailed proof-of-concept examples for each vulnerability.
Nuclei Templates (1)
http.html:"soplanning"
body="soplanning"
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N