vendor:
OsClass
by:
Omar Kurt
9
CVSS
CRITICAL
Local File Inclusion
N/A
CWE
Product Name: OsClass
Affected Version From: 3.4.1
Affected Version To: 3.4.1
Patch Exists: YES
Related CWE: CVE-2014-6308
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: cve,cve2014,lfi,packetstorm
CVSS Metrics: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
Nuclei References:
https://packetstormsecurity.com/files/128285/OsClass-3.4.1-Local-File-Inclusion.html, https://nvd.nist.gov/vuln/detail/CVE-2014-6308, https://github.com/osclass/Osclass/commit/c163bf5910d0d36424d7fc678da6b03a0e443435, https://www.netsparker.com/lfi-vulnerability-in-osclass/, http://blog.osclass.org/2014/09/15/osclass-3-4-2-ready-download/
Nuclei Metadata: {'max-request': 1, 'vendor': 'osclass', 'product': 'osclass'}
Platforms Tested: N/A
2014
LFI Vulnerability in OsClass
A directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a render action to oc-admin/index.php.
Mitigation:
Fix released publicly in Osclass 3.4.2