CVE-2020-25068
HIGHSetelsa Conacwin v3.7.1.2 - Unauthenticated Local File Inclusion via Directory Traversal URI
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-25068. PoCs published by bryanroma.
AI-analyzed exploit summary This is a Python-based exploit for CVE-2020-25068, targeting a local file inclusion (LFI) vulnerability in Setelsa Conacwin v3.7.1.2. The exploit allows unauthenticated remote attackers to read arbitrary files on the server via directory traversal sequences.
Description
Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server via an http:IP:PORT/../../path/file_to_disclose Directory Traversal URI. NOTE: The manufacturer indicated that the affected version does not exist. Furthermore, they indicated that they detected this problem in an internal audit more than 3 years ago and fixed it in 2017.
Exploits (1)
This is a Python-based exploit for CVE-2020-25068, targeting a local file inclusion (LFI) vulnerability in Setelsa Conacwin v3.7.1.2. The exploit allows unauthenticated remote attackers to read arbitrary files on the server via directory traversal sequences.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N