CVE-2014-9582

Codiad 2.4.3 - Cross-Site Scripting via Filemanager Rename Short Name Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-9582. PoCs published by TaurusOmar.

AI-analyzed exploit summary The exploit demonstrates a Cross-Site Scripting (XSS) vulnerability and a Local File Inclusion (LFI) vulnerability in Codiad 2.4.3. The XSS is triggered via the 'short_name' parameter, while the LFI allows reading arbitrary files like '/etc/passwd' via path traversal in the 'path' parameter.

Description

Cross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to inject arbitrary web script or HTML via the short_name parameter in a rename action. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more information.

Exploits (1)

exploitdb WORKING POC
by TaurusOmar · textwebappsphp
https://www.exploit-db.com/exploits/35585

The exploit demonstrates a Cross-Site Scripting (XSS) vulnerability and a Local File Inclusion (LFI) vulnerability in Codiad 2.4.3. The XSS is triggered via the 'short_name' parameter, while the LFI allows reading arbitrary files like '/etc/passwd' via path traversal in the 'path' parameter.

Classification
Working Poc 90%
Attack Type
Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Codiad 2.4.3
No auth needed
Prerequisites: access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35585

Scores

EPSS 0.0147
EPSS Percentile 70.4%

Details

CWE
CWE-79
Status published
Products (1)
codiad/codiad 2.4.3
Published Jan 08, 2015
Tracked Since Feb 18, 2026