Record summary

CVE-2015-4666 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBXceedium Xsuite - Multiple VulnerabilitiesExploitDB exploitby modzeroNot analyzed1 file

linked to 6 vulnerabilities

ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMXceedium Xsuite <=2.4.4.5 - Local File InclusionCVSS 5

Xceedium Xsuite 2.4.4.5 and earlier is vulnerable to local file inclusion via opm/read_sessionlog.php that allows remote attackers to read arbitrary files in the logFile parameter.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access, disclosure of sensitive information, and potential remote code execution.

Remediation

Upgrade Xceedium Xsuite to a version higher than 2.4.4.5 or apply the necessary patches provided by the vendor.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2015cvexceediumxsuitelfipacketstormxssvuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
CPE: cpe:2.3:a:xceedium:xsuite:2.3.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5