CVE-2014-9581

Codiad 2.4.3 - Path Traversal via File Manager Download Path Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-9581. PoCs published by TaurusOmar.

AI-analyzed exploit summary The exploit demonstrates a Cross-Site Scripting (XSS) vulnerability and a Local File Inclusion (LFI) vulnerability in Codiad 2.4.3. The XSS is triggered via the 'short_name' parameter, while the LFI allows reading arbitrary files like '/etc/passwd' via path traversal in the 'path' parameter.

Description

Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more information.

Exploits (1)

exploitdb WORKING POC
by TaurusOmar · textwebappsphp
https://www.exploit-db.com/exploits/35585

The exploit demonstrates a Cross-Site Scripting (XSS) vulnerability and a Local File Inclusion (LFI) vulnerability in Codiad 2.4.3. The XSS is triggered via the 'short_name' parameter, while the LFI allows reading arbitrary files like '/etc/passwd' via path traversal in the 'path' parameter.

Classification
Working Poc 90%
Attack Type
Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Codiad 2.4.3
No auth needed
Prerequisites: access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35585

Scores

EPSS 0.0358
EPSS Percentile 87.9%

Details

CWE
CWE-22
Status published
Products (1)
codiad/codiad 2.4.3
Published Jan 08, 2015
Tracked Since Feb 18, 2026