5
CVSSv2

CVE-2014-5115

Published: 29/07/2014 Updated: 27/08/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Absolute path traversal vulnerability in DirPHP 1.0 allows remote malicious users to read arbitrary files via a full pathname in the phpfile parameter to index.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dirphp project dirphp 1.0

Exploits

# Exploit Title: DirPHP - version 10 Local File Inclusion # Google Dork: intext:DirPHP - version 10 - Created & Maintained by Stuart Montgomery # Date: 7/26/14 # Exploit Author: -Chosen- # Contact: dark[dot]binary[dot]code@gmailcom # Version: DirPHP - Version 10 # Tested on: *nix PoC: sitecom/path/indexphp?phpfile=/etc/passwd ...