CVE-2017-9833
HIGH EXPLOITED IN THE WILD NUCLEIBoa 0.94.14rc21 - Path Traversal via FILECAMERA Parameter
Title source: llmExploitation Summary
CVE-2017-9833 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 2 public exploits from researchers including Miguel Mendez Z, anldori. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in BOA Web Server 0.94.14, allowing arbitrary file access via the FILECAMERA parameter. The PoC shows how to read sensitive files like /etc/shadow without authentication.
Description
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.
Exploits (2)
This exploit demonstrates a directory traversal vulnerability in BOA Web Server 0.94.14, allowing arbitrary file access via the FILECAMERA parameter. The PoC shows how to read sensitive files like /etc/shadow without authentication.
This PoC demonstrates a directory traversal vulnerability in Boa Web Server 0.94.14rc21, allowing unauthorized access to sensitive files like /etc/shadow via a crafted CGI request.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N