CVE-2018-10956
HIGH NUCLEIIPConfigure Orchid Core VMS 2.0.5 - Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-10956. PoCs published by Nettitude. A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability in IPConfigure Orchid VMS <=2.0.5, allowing unauthenticated remote attackers to read arbitrary files on the system. The exploit sends crafted GET requests with traversal sequences to retrieve sensitive files like /etc/passwd.
Description
IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
Exploits (1)
This Metasploit module exploits a directory traversal vulnerability in IPConfigure Orchid VMS <=2.0.5, allowing unauthenticated remote attackers to read arbitrary files on the system. The exploit sends crafted GET requests with traversal sequences to retrieve sensitive files like /etc/passwd.
Nuclei Templates (1)
http.title:"Orchid Core VMS" || http.title:"orchid core vms"
title="orchid core vms"
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N