Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-8722. PoCs published by Ron Jost.
AI-analyzed exploit summary This exploit leverages an information disclosure vulnerability in GetSimple CMS 3.3.4 by directly accessing sensitive XML files (e.g., authorization.xml, user data) without authentication. It retrieves API keys, hashed passwords, and email addresses via HTTP requests.
Description
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<username>.xml.bak, (3) data/other/authorization.xml, or (4) data/other/appid.xml.
Exploits (1)
This exploit leverages an information disclosure vulnerability in GetSimple CMS 3.3.4 by directly accessing sensitive XML files (e.g., authorization.xml, user data) without authentication. It retrieves API keys, hashed passwords, and email addresses via HTTP requests.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N