Record summary

CVE-2019-11013 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of the restricted directory on the remote server.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBNimble Streamer 3.0.2-2 < 3.5.4-9 - Directory TraversalExploitDB exploitby MaYaSeVeNNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMNimble Streamer <=3.5.4-9 - Local File InclusionCVSS 6.5

Nimble Streamer 3.0.2-2 through 3.5.4-9 is vulnerable to local file inclusion. An attacker can traverse the file system to access files or directories that are outside of the restricted directory on the remote server.

Impact

The LFI vulnerability can lead to unauthorized access to sensitive files, potential data leakage, and further exploitation of the system.

Remediation

Upgrade Nimble Streamer to a version higher than 3.5.4-9 to mitigate the LFI vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2019lfinimbleedbpacketstormsoftvelumvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:softvelum:nimble_streamer:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3