← Vulnerability feed

Vulnerability record · CVE-2014-8676 · published 31 August 2017

CVE-2014-8676: Soplanning path traversal vulnerability

Soplanning · Soplanning

Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.

5.3 CVSS 3.0 Medium EPSS 41% · top 1.4% CWE-22 · Path traversal
5.3CVSS 3.0 base score, v2 5.0
41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-8676 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-27115Soplanning unrestricted file upload vulnerabilityA unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker ca…EPSS 4.6%9.8CVE-2024-57169Soplanning unrestricted file upload vulnerabilityA file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to b…EPSS 0.97%9.8CVE-2020-13963Soplanning hard-coded credentials vulnerabilitySOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The …EPSS 1.8%9.8CVE-2014-8673Soplanning sql injection vulnerabilityMultiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPP…EPSS 12%9.3CVE-2024-27112Soplanning sql injection vulnerabilityA unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use thi…EPSS 0.41%9.3CVE-2024-27113Soplanning information exposure vulnerabilityAn unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view se…EPSS 0.43%8.9CVE-2024-27114Soplanning toctou race condition vulnerabilityA unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, …EPSS 0.54%8.8CVE-2019-20179Soplanning sql injection vulnerabilitySOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2014-8676), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.