PoC Index

CVE-2014-2383

MEDIUM 6.8EPSS 39.2%

dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/read=convert.base64-encode/resource in the input_file parameter.

CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
39.23% chance of exploitation in the next 30 days, 98th percentile
Nuclei
medium · CWE-200
Published
2014-04-28
Updated
2024-08-06

Proof-of-concept exploits (1)

Nuclei templates (1)

ExploitDB entries (1)

References

Related