projectxit.com.au
http://www.projectxit.com.au/blog/2018/2/27/axxonsoft-client-directory-traversal-cve-2018-7467-axxonsoft-axxon-next-axxonsoft-client-directory-traversal-via-an-initial-css2f-substring-in-a-uri-cve-2018-7467 CVE-2018-7467
HIGHNuclei
AxxonSoft Axxon Next - Local File Inclusion
Record summary
CVE-2018-7467 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHAxxonSoft Axxon Next - Local File InclusionCVSS 7.5
AxxonSoft Axxon Next suffers from a local file inclusion vulnerability.
Impact
An attacker can read sensitive files, execute arbitrary code, or launch further attacks.
Remediation
Apply the latest security patches or updates provided by AxxonSoft to fix the local file inclusion vulnerability.
WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2018axxonsoftlfipacketstormvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:axxonsoft:next:-:*:*:*:*:*:*:*
https://packetstormsecurity.com/files/146604/AxxonSoft-Axxon-Next-Directory-Traversal.html https://github.com/sullo/advisory-archives/blob/master/axxonsoft-next-CVE-2018-7467.txt https://nvd.nist.gov/vuln/detail/CVE-2018-7467 http://www.projectxit.com.au/blog/2018/2/27/axxonsoft-client-directory-traversal-cve-2018-7467-axxonsoft-axxon-next-axxonsoft-client-directory-traversal-via-an-initial-css2f-substring-in-a-uri-cve-2018-7467 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-7467