packetstormsecurity.com
http://packetstormsecurity.com/files/132142/ResourceSpace-7.1.6513-Local-File-Inclusion.html CVE-2015-3648
Nuclei
ResourceSpace - Local File inclusion
Record summary
CVE-2015-3648 has a selected CVSS score of 7.5; EIP currently links 1 Nuclei template.
Description
Directory traversal vulnerability in pages/setup.php in Montala Limited ResourceSpace before 7.2.6727 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the defaultlanguage parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHResourceSpace - Local File inclusionCVSS 7.5
ResourceSpace is prone to a local file-inclusion vulnerability because it fails to sufficiently sanitize user-supplied input.
Impact
An attacker can exploit this vulnerability to read sensitive files, execute arbitrary code, or launch further attacks.
Remediation
Upgrade to the latest version of ResourceSpace to fix the local file inclusion vulnerability.
WeaknessesCWE-22
Authorspikpikcu
Template tagscve2015cvelfiresourcespacepacketstormmontalavuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
CPE: cpe:2.3:a:montala:resourcespace:*:*:*:*:*:*:*:*
https://vulners.com/cve/CVE-2015-3648/ http://svn.montala.com/websvn/revision.php?repname=ResourceSpace&path=%2F&rev=6640&peg=6738 http://packetstormsecurity.com/files/132142/ResourceSpace-7.1.6513-Local-File-Inclusion.html https://nvd.nist.gov/vuln/detail/CVE-2015-3648 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
6svn.montala.comConfirmation
http://svn.montala.com/websvn/revision.php?repname=ResourceSpace&path=%2F&rev=6640&peg=6738 20150603 Local PHP File Inclusion in ResourceSpacemailing list
http://www.securityfocus.com/archive/1/535669/100/0/threaded 75019vdb entry
http://www.securityfocus.com/bid/75019 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-3648 htbridge.com
https://www.htbridge.com/advisory/HTB23258