CVE-2019-11013
Nimble Streamer 3.0.2-2 < 3.5.4-9 - Directory Traversal
Record summary
CVE-2019-11013 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of the restricted directory on the remote server.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBNimble Streamer 3.0.2-2 < 3.5.4-9 - Directory TraversalExploitDB exploitby MaYaSeVeNNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMNimble Streamer <=3.5.4-9 - Local File InclusionCVSS 6.5
Nimble Streamer 3.0.2-2 through 3.5.4-9 is vulnerable to local file inclusion. An attacker can traverse the file system to access files or directories that are outside of the restricted directory on the remote server.
Impact
The LFI vulnerability can lead to unauthorized access to sensitive files, potential data leakage, and further exploitation of the system.
Remediation
Upgrade Nimble Streamer to a version higher than 3.5.4-9 to mitigate the LFI vulnerability.
Source: ProjectDiscovery