CVE-2018-13864
HIGHPlay Framework 2.6.12-2.6.15 - Path Traversal via Assets Controller
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-13864. PoCs published by tafamace.
AI-analyzed exploit summary The provided code is a simple Java stub that prints command-line arguments and does not demonstrate any exploit functionality for CVE-2018-13864. It lacks any offensive techniques or vulnerability exploitation logic.
Description
A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when running on Windows. It allows a remote attacker to download arbitrary files from the target server via specially crafted HTTP requests.
Exploits (1)
The provided code is a simple Java stub that prints command-line arguments and does not demonstrate any exploit functionality for CVE-2018-13864. It lacks any offensive techniques or vulnerability exploitation logic.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N