PoC Index

CVE-2011-1715

MEDIUM 5.0EPSS 8.9%

Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows remote attackers to read arbitrary files via ..%2f (encoded dot dot) sequences in the file parameter.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
8.88% chance of exploitation in the next 30 days, 95th percentile
Published
2011-04-18
Updated
2024-08-06

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related