GHSA-39jc-xvx2-95jhHighCVSS 7.5
The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php...
🔗 CVE IDs covered (1)
📋 Description
The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the filename parameter. Attackers can supply directory traversal sequences ../ in the filename parameter to access files outside the intended directory, including configuration files and system files.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2018-25408
- https://sourceforge.net/projects/openises/files/latest/download
- https://www.exploit-db.com/exploits/45655
- https://www.vulncheck.com/advisories/the-open-ises-project-3-30a-path-traversal-arbitrary-file-download
- http://openises.sourceforge.net
- https://github.com/advisories/GHSA-39jc-xvx2-95jh