vendor:
Easy File Sharing Web Server
by:
Touhid M.Shaikh
8,8
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Easy File Sharing Web Server
Affected Version From: 7.2
Affected Version To: 7.2
Patch Exists: NO
Related CWE: N/A
CPE: a:efs_software:easy_file_sharing_web_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
EFS Web Server 7.2 Authentication Bypass
Easy File Sharing Web Server is a file sharing software that allows visitors to upload/download files easily through a Web Browser. An attacker can bypass the login screen by changing the URL and browsing the drives. The attacker can then view drives and folders and download files from different drives or folders.
Mitigation:
Ensure that authentication is properly implemented and enforced.