96823vdb entry
http://www.securityfocus.com/bid/96823 CVE-2017-6528
HIGH
dnaLIMS DNA Sequencing - Directory Traversal / Session Hijacking / Cross-Site Scripting
Record summary
CVE-2017-6528 has a selected CVSS score of 8.1 (high); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/spool/.pfile file).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBdnaLIMS DNA Sequencing - Directory Traversal / Session Hijacking / Cross-Site ScriptingExploitDB exploitby Shorebreak SecurityNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-6528 41578exploit
https://www.exploit-db.com/exploits/41578 shorebreaksecurity.com
https://www.shorebreaksecurity.com/blog/product-security-advisory-psa0002-dnalims