Unrated severityNVD Advisory· Published Oct 20, 2014· Updated May 6, 2026
CVE-2014-6308
CVE-2014-6308
Description
Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a render action to oc-admin/index.php.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- packetstormsecurity.com/files/128285/OsClass-3.4.1-Local-File-Inclusion.htmlnvdExploit
- github.com/osclass/Osclass/commit/c163bf5910d0d36424d7fc678da6b03a0e443435nvdExploit
- blog.osclass.org/2014/09/15/osclass-3-4-2-ready-download/nvd
- www.securityfocus.com/archive/1/533456/100/0/threadednvd
- www.netsparker.com/lfi-vulnerability-in-osclass/nvd
News mentions
0No linked articles in our index yet.