CVE-2015-4666
NUCLEIXceedium Xsuite - Directory Traversal via opm/read_sessionlog.php logFile Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-4666. PoCs published by modzero. A Nuclei detection template is also available.
AI-analyzed exploit summary This is a detailed security advisory describing multiple vulnerabilities in Xceedium Xsuite, including command injection, XSS, directory traversal, privilege escalation, and hard-coded credentials. It provides proof-of-concept HTTP requests and code snippets to demonstrate the vulnerabilities.
Description
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.
Exploits (1)
This is a detailed security advisory describing multiple vulnerabilities in Xceedium Xsuite, including command injection, XSS, directory traversal, privilege escalation, and hard-coded credentials. It provides proof-of-concept HTTP requests and code snippets to demonstrate the vulnerabilities.