Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-17876. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates a local file download vulnerability in Biometric Shift Employee Management System 3.0. It allows an attacker to download arbitrary local files by manipulating the 'name' and 'path' parameters in the URL.
Description
Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pathname in the path parameter.
Exploits (1)
This exploit demonstrates a local file download vulnerability in Biometric Shift Employee Management System 3.0. It allows an attacker to download arbitrary local files by manipulating the 'name' and 'path' parameters in the URL.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N