CVE-2014-0780
CRITICAL KEVInduSoft Web Studio 7.1 - Path Traversal and Arbitrary Code Execution via NTWebServer
Title source: llmExploitation Summary
CVE-2014-0780 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added April 15, 2022. EIP tracks 1 public exploit from researchers including James Fitts.
AI-analyzed exploit summary This Metasploit auxiliary module exploits a directory traversal vulnerability in Indusoft Web Studio <= 7.1 before SP2 Patch 4, allowing unauthorized file downloads from the underlying system. It sends a crafted HTTP GET request with traversal sequences to retrieve files like 'boot.ini'.
Description
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.
Exploits (1)
This Metasploit auxiliary module exploits a directory traversal vulnerability in Indusoft Web Studio <= 7.1 before SP2 Patch 4, allowing unauthorized file downloads from the underlying system. It sends a crafted HTTP GET request with traversal sequences to retrieve files like 'boot.ini'.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H