Record summary

CVE-2018-7467 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHAxxonSoft Axxon Next - Local File InclusionCVSS 7.5

AxxonSoft Axxon Next suffers from a local file inclusion vulnerability.

Impact

An attacker can read sensitive files, execute arbitrary code, or launch further attacks.

Remediation

Apply the latest security patches or updates provided by AxxonSoft to fix the local file inclusion vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2018axxonsoftlfipacketstormvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:axxonsoft:next:-:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2