vendor:
E-Detective Lawful Interception System
by:
Mustafa Al-Bassam, slipstream/RoL
8.8
CVSS
HIGH
Unauthenticated Local File Disclosure
22
CWE
Product Name: E-Detective Lawful Interception System
Affected Version From: All versions
Affected Version To: All versions
Patch Exists: YES
Related CWE: unassigned
CPE: a:decision_group:e-detective_lawful_interception_system
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2015
Advisory: E-Detective Lawful Interception System multiple security vulnerabilities
Proof-of-concept for unauthenticated LFD in E-Detective. Authors: Mustafa Al-Bassam (https://musalbas.com) slipstream/RoL (https://twitter.com/TheWack0lian). The proof-of-concept uses the 'action=getfile&file=' parameter to read arbitrary files on the server.
Mitigation:
Upgrade to the latest version of E-Detective.