CVE-2020-27993
MEDIUMhrsale 2.0.0 - Path Traversal via Download Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-27993. PoCs published by Sosecure.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Hrsale 2.0.0, allowing unauthorized access to readable files on the server via a crafted URL. The payload targets the `/download` endpoint with directory traversal sequences to retrieve sensitive files like `/etc/passwd`.
Description
Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Hrsale 2.0.0, allowing unauthorized access to readable files on the server via a crafted URL. The payload targets the `/download` endpoint with directory traversal sequences to retrieve sensitive files like `/etc/passwd`.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N