CVE-2016-20029
MEDIUMZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2016-20029. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates a file path manipulation vulnerability in ZKTeco ZKBioSecurity 3.0, allowing an attacker to access sensitive files (e.g., web.xml) by traversing directories via a crafted URL. The PoC provides a direct example of the vulnerable endpoint and payload.
Description
ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipulate path parameters to bypass access controls and retrieve sensitive information including configuration files, source code, and protected application resources.
Exploits (1)
The exploit demonstrates a file path manipulation vulnerability in ZKTeco ZKBioSecurity 3.0, allowing an attacker to access sensitive files (e.g., web.xml) by traversing directories via a crafted URL. The PoC provides a direct example of the vulnerable endpoint and payload.
References (6)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N