505
VMScore

CVE-2014-8676

Published: 31/08/2017 Updated: 05/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and previous versions allows remote malicious users to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

soplanning soplanning

Exploits

SOPlanning - Simple Online Planning Tool multiple vulnerabilities CVEs: CVE-2014-8673, CVE-2014-8674, CVE-2014-8675, CVE-2014-8676, CVE-2014-8677 Vendor: wwwsoplanningorg/ Product: SOPlanning - Simple Online Planning Version affected: 132 and prior Product description: SO Planning is an open source online planning tool completely free, ...
Simple Online Planning Tool version 132 suffers from code execution, cross site scripting, remote SQL injection, information disclosure, and path traversal vulnerabilities ...