Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-14537. PoCs published by Ron Jost. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a path traversal vulnerability in Trixbox 2.8.0.4 via the 'lang' parameter in /maint/modules/home/index.php. It allows an attacker to read arbitrary files on the system by traversing directories.
Description
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
Exploits (1)
This exploit demonstrates a path traversal vulnerability in Trixbox 2.8.0.4 via the 'lang' parameter in /maint/modules/home/index.php. It allows an attacker to read arbitrary files on the system by traversing directories.
Nuclei Templates (1)
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N