Record summary

CVE-2017-6527 has a selected CVSS score of 7.5 (high); EIP currently links 2 catalogued exploits.

Description

An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticated attacker to access system files readable by the web server user (by using the viewAppletFsa.cgi seqID parameter).

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBdnaLIMS DNA Sequencing - Directory Traversal / Session Hijacking / Cross-Site ScriptingExploitDB exploitby Shorebreak SecurityNot analyzed1 file

linked to 4 vulnerabilities

ExploitDB

PoC details
MetasploitDnaLIMS Directory TraversalMetasploit auxiliary PoCby flakey_biscuit <nicholas@shorebreaksecurity.com> +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

4