Record summary

CVE-2018-8727 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Path Traversal in Gateway in Mirasys DVMS Workstation 5.12.6 and earlier allows an attacker to traverse the file system to access files or directories via the Web Client webserver.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHMirasys DVMS Workstation <=5.12.6 - Local File InclusionCVSS 7.5

Mirasys DVMS Workstation versions 5.12.6 and prior suffer from local file inclusion vulnerabilities.

Impact

An attacker can exploit this vulnerability to gain unauthorized access to sensitive information, potentially leading to further compromise of the system.

Remediation

Upgrade to a patched version of Mirasys DVMS Workstation (>=5.12.7) to mitigate the LFI vulnerability.

WeaknessesCWE-22
Authors0x_akoko
Template tagscvecve2018mirasyslfipacketstormvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:mirasys:dvms_workstation:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2