CVE-2020-15928

MEDIUM

Ortus TestBox 2.4.0-4.1.0 - Path Traversal via test-browser/index.cfm Query Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-15928. PoCs published by Darren King.

AI-analyzed exploit summary This is a writeup describing a directory traversal vulnerability in TestBox CFML Test Framework versions 2.3.0 through 4.1.0. The vulnerability allows an attacker to traverse directories via the 'path' QueryString parameter in the test-browser page.

Description

In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal.

Exploits (1)

exploitdb WRITEUP
by Darren King · textwebappsmultiple
https://www.exploit-db.com/exploits/49078

This is a writeup describing a directory traversal vulnerability in TestBox CFML Test Framework versions 2.3.0 through 4.1.0. The vulnerability allows an attacker to traverse directories via the 'path' QueryString parameter in the test-browser page.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: TestBox CFML Test Framework 2.3.0 through 4.1.0
No auth needed
Prerequisites: TestBox deployed in a web-accessible directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/49078

Scores

CVSS v3 5.3
EPSS 0.0171
EPSS Percentile 74.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
ortussolutions/testbox 2.4.0 - 4.1.0
Published Nov 24, 2020
Tracked Since Feb 18, 2026