CVE-2020-15928
MEDIUMOrtus TestBox 2.4.0-4.1.0 - Path Traversal via test-browser/index.cfm Query Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-15928. PoCs published by Darren King.
AI-analyzed exploit summary This is a writeup describing a directory traversal vulnerability in TestBox CFML Test Framework versions 2.3.0 through 4.1.0. The vulnerability allows an attacker to traverse directories via the 'path' QueryString parameter in the test-browser page.
Description
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal.
Exploits (1)
This is a writeup describing a directory traversal vulnerability in TestBox CFML Test Framework versions 2.3.0 through 4.1.0. The vulnerability allows an attacker to traverse directories via the 'path' QueryString parameter in the test-browser page.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N