vendor:
d-COPIA253MF plus
by:
Hakan Eren ŞAN
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: d-COPIA253MF plus
Affected Version From: d-COPIA253MF plus
Affected Version To: d-COPIA253MF plus
Patch Exists: NO
Related CWE: N/A
CPE: h:kyocera:d-copia253mf_plus
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2020
Kyocera Printer d-COPIA253MF – Directory Traversal (PoC)
An attacker can exploit a directory traversal vulnerability in Kyocera Printer d-COPIA253MF by sending a specially crafted HTTP request containing a directory traversal payload followed by a null byte (%00). This allows the attacker to access files outside of the web root directory.
Mitigation:
Ensure that user input is validated and sanitized to prevent directory traversal attacks.