Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-53902. PoCs published by Mirabbas Ağalarov.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in WebsiteBaker v2.13.3, allowing arbitrary directory deletion via a crafted GET request. The PoC shows how an attacker can delete directories outside the intended scope by manipulating the 'dir' parameter.
Description
WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in WebsiteBaker v2.13.3, allowing arbitrary directory deletion via a crafted GET request. The PoC shows how an attacker can delete directories outside the intended scope by manipulating the 'dir' parameter.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N