vendor:
HiveOS
by:
Rik van Duijn
7,5
CVSS
HIGH
XSS and LFI
79 (XSS) and 22 (LFI)
CWE
Product Name: HiveOS
Affected Version From: 5.1r5
Affected Version To: 6.1r5
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014
Aerohive HiveOS XSS and (limited) LFI
Aerohive version 5.1r5 through 6.1r5 contain two vulnerabilities, one reflective XSS vulnerability and a limited local file inclusion vulnerability (I was only able to view source from one specific folder, maybe you can leverage this further). It's possible earlier version are affected, I was only able to review 5.1r5 briefly, the vendor indicated other version up to 6.1r5 are vulnerable as well.
Mitigation:
Upgrade to version 6.1r5 or later