Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2014-8676 PoC — SOPlanning 路径遍历漏洞

Source
Associated Vulnerability
Title:SOPlanning 路径遍历漏洞 (CVE-2014-8676)
Description:SOPlanning是一套免费且开源的在线项目生产和管理工具。 SOPlanning 1.32及之前的版本中的‘file_get_contents’函数存在目录遍历漏洞。远程攻击者可借助URL路径参数利用该漏洞检测任意文件是否存在。
Description
SOPlanning <1.32 contain a directory traversal in the file_get_contents function via a .. (dot dot) in the fichier parameter.
File Snapshot

id: CVE-2014-8676 info: name: Simple Online Planning Tool <1.3.2 - Local File Inclusion author: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.