CVE-2020-29134
HIGHTOTVS Fluig - Path Traversal via Base64-Encoded File Parameter
Title source: llmExploitation Summary
EIP tracks 4 public exploits for CVE-2020-29134. PoCs published by Lucas Souza, Ls4ss.
AI-analyzed exploit summary This script exploits a path traversal vulnerability in Fluig 1.7.0, allowing unauthorized access to sensitive files such as domain.xml, passwd, and desktop.ini. It uses wfuzz to enumerate paths and curl to retrieve file contents, demonstrating the vulnerability effectively.
Description
The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all versions Fluig Lake 1.7.0, Fluig 1.6.5 and Fluig 1.6.4
Exploits (4)
This script exploits a path traversal vulnerability in Fluig 1.7.0, allowing unauthorized access to sensitive files such as domain.xml, passwd, and desktop.ini. It uses wfuzz to enumerate paths and curl to retrieve file contents, demonstrating the vulnerability effectively.
This repository contains a functional exploit script for CVE-2020-29134, a path traversal vulnerability in TOTVS Fluig Platform. The script automates the exploitation process by generating base64-encoded payloads to read sensitive files like domain.xml, which may contain database credentials and LDAP configurations.
This repository contains a functional exploit script for CVE-2020-29134, a path traversal vulnerability in TOTVS Fluig Platform. The script automates the exploitation process, allowing attackers to read sensitive files like domain.xml, which contains database credentials and LDAP configurations.
This repository contains a functional exploit script for CVE-2020-29134, a path traversal vulnerability in TOTVS Fluig Platform. The script automates the exploitation process by generating base64-encoded payloads to read sensitive files like domain.xml, /etc/passwd, and other system files.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N