44350exploit
https://exploit-db.com/exploits/44350 CVE-2018-9148
CRITICAL
TwonkyMedia Server 7.0.11-8.5 - Directory Traversal
Record summary
CVE-2018-9148 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CVE-2018-7171 for remote authentication bypass within a product that uses My Cloud.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTwonkyMedia Server 7.0.11-8.5 - Directory TraversalExploitDB exploitby Sven FassbenderNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-9148