seclists.org
http://seclists.org/bugtraq/2017/Sep/20 CVE-2017-14680
HIGH
ZKTime Web Software 2.0 - Improper Access Restrictions
Record summary
CVE-2017-14680 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBZKTime Web Software 2.0 - Improper Access RestrictionsExploitDB exploitby Arvind VNot analyzed1 file
References
3seclists.org
http://seclists.org/fulldisclosure/2017/Sep/39 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-14680