CVE-2020-35598
HIGHNuclei
Advanced Comment System 1.0 - 'ACS_path' Path Traversal
Record summary
CVE-2020-35598 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBAdvanced Comment System 1.0 - 'ACS_path' Path TraversalExploitDB exploitby Francisco Javier Santiago VázquezNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHAdvanced Comment System 1.0 - Local File InclusionCVSS 7.5
ACS Advanced Comment System 1.0 is affected by local file inclusion via an advanced_component_system/index.php?ACS_path=..%2f URI.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire system.
Remediation
Apply the latest patch or update provided by the vendor to fix the local file inclusion vulnerability in the Advanced Comment System 1.0.
WeaknessesCWE-22
Authorsdaffainfo
Template tagscvecve2020acsedbseclistslfiadvanced_comment_system_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:advanced_comment_system_project:advanced_comment_system:1.0:*:*:*:*:*:*:*
https://www.exploit-db.com/exploits/49343 https://seclists.org/fulldisclosure/2020/Dec/13 https://nvd.nist.gov/vuln/detail/CVE-2020-35598 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-35598 seclists.org
https://seclists.org/fulldisclosure/2020/Dec/13