96823vdb entry
http://www.securityfocus.com/bid/96823 CVE-2017-6527
HIGH
dnaLIMS DNA Sequencing - Directory Traversal / Session Hijacking / Cross-Site Scripting
Record summary
CVE-2017-6527 has a selected CVSS score of 7.5 (high); EIP currently links 2 catalogued exploits.
Description
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticated attacker to access system files readable by the web server user (by using the viewAppletFsa.cgi seqID parameter).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBdnaLIMS DNA Sequencing - Directory Traversal / Session Hijacking / Cross-Site ScriptingExploitDB exploitby Shorebreak SecurityNot analyzed1 file
MetasploitDnaLIMS Directory TraversalMetasploit auxiliary PoCby flakey_biscuit <nicholas@shorebreaksecurity.com> +1 moreNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-6527 41578exploit
https://www.exploit-db.com/exploits/41578 shorebreaksecurity.com
https://www.shorebreaksecurity.com/blog/product-security-advisory-psa0002-dnalims