CVE-2020-29134

HIGH

Totvs Fluig - Path Traversal

Title source: rule

Description

The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all versions Fluig Lake 1.7.0, Fluig 1.6.5 and Fluig 1.6.4

Exploits (4)

exploitdb WORKING POC
by Lucas Souza · bashwebappsmultiple
https://www.exploit-db.com/exploits/49622
nomisec WORKING POC 3 stars
by Ls4ss · poc
https://github.com/Ls4ss/CVE-2020-29134
inthewild WORKING POC
poc
https://github.com/lucxssouza/cve-2020-29134
inthewild WORKING POC
poc
https://github.com/lsass-exe/cve-2020-29134

Scores

CVSS v3 8.6
EPSS 0.2033
EPSS Percentile 95.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (3)
totvs/fluig 1.6.4
totvs/fluig 1.6.5
totvs/fluig 1.7.0
Published Mar 05, 2021
Tracked Since Feb 18, 2026