vendor:
Zen Load Balancer
by:
Basim Alabdullah, Dhiraj Mishra
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Zen Load Balancer
Affected Version From: v3.10.1
Affected Version To: v3.10.1
Patch Exists: YES
Related CWE: EDB-48308
CPE: a:zenloadbalancer:zen_load_balancer
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
Zen Load Balancer Directory Traversal
This module exploits a authenticated directory traversal vulnerability in Zen Load Balancer `v3.10.1`. The flaw exists in 'index.cgi' not properly handling 'filelog=' parameter which allows a malicious actor to load arbitrary file path.
Mitigation:
Update to the latest version of Zen Load Balancer