vendor:
Ws02Carbon
by:
John Page aka HYP3RLINX
4,9
CVSS
MEDIUM
Local File Inclusion (LFI)
22
CWE
Product Name: Ws02Carbon
Affected Version From: v4.4.5
Affected Version To: v4.4.5
Patch Exists: YES
Related CWE: CVE-2016-4314
CPE: a:wso2:wso2_carbon:4.4.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
WSO2 Carbon v4.4.5 Local File Inclusion
An authenticated user can download configuration files in the filesystem via downloadArchivedLogFiles operation in LogViewer admin service. The request to the admin service accepts a file path relative to the carbon log file directory (i.e. <WSO2_PRODUCT_HOME>/repository/logs) hence can access any file in the file system.
Mitigation:
Restrict access to the LogViewer admin service and ensure that the user has the least privilege to access the service.