CVE-2018-12632
MEDIUMRedatam < 7 - Information Disclosure via Invalid LFN Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-12632. PoCs published by Berk Dusunur.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Redatam Web Server before version 7. By manipulating the LFN parameter, an attacker can leak directory structures and access arbitrary files on the server.
Description
Redatam7 (formerly Redatam WebServer) allows remote attackers to discover the installation path via an invalid LFN parameter to the /redbin/rpwebutilities.exe/text URI.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in Redatam Web Server before version 7. By manipulating the LFN parameter, an attacker can leak directory structures and access arbitrary files on the server.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N