vendor:
Open ISES Project
by:
Ihsan Sencan
7.5
CVSS
HIGH
Arbitrary File Download
434
CWE
Product Name: Open ISES Project
Affected Version From: 3.30A_050318
Affected Version To: 3.30A_050318
Patch Exists: NO
Related CWE: N/A
CPE: a:openises:open_ises_project:3.30a_050318
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2018
The Open ISES Project 3.30A – Arbitrary File Download
The Open ISES Project 3.30A is vulnerable to an arbitrary file download vulnerability. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable server. This request contains a malicious filename parameter which can be used to download any file from the server. The attacker can also use the origname parameter to download any file from the server.
Mitigation:
The application should validate the filename parameter and should not allow any malicious input. The application should also restrict the access to the download.php file.