5
CVSSv2

CVE-2014-9261

Published: 23/03/2015 Updated: 18/02/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote malicious users to read arbitrary files via a .. (dot dot) in the path parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

codologic codoforum 2.5.1

Exploits

# Exploit Title: Codoforum 251 Arbitrary File Download # Date: 23-11-2014 # Software Link: codoforumcom/ # Exploit Author: Kacper Szurek # Contact: twittercom/KacperSzurek # Website: securityszurekpl/ # Category: webapps # CVE: CVE-2014-9261 1 Description str_replace() is used to sanitize file path but function outp ...