Record summary

CVE-2020-6950 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 2.3.14 · Fixed in 2.3.14affected

Nuclei templates

1
ProjectDiscoveryMEDIUMEclipse Mojarra - Local File ReadCVSS 6.5

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

Impact

Attackers can read arbitrary files from the server including configuration files and credentials, potentially leading to further exploitation and data exposure.

Remediation

Upgrade to Eclipse Mojarra version 2.3.14 or later.

WeaknessesCWE-22
Authorsiamnoooob, pdresearch
Template tagscvecve2020mojarralfieclipsevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:eclipse:mojarra:*:*:*:*:*:*:*:*
Shodan: html:"javax.faces.resource"
Shodan: http.html:"javax.faces.viewstate"
Shodan: http.html:"javax.faces.resource"
FOFA: body="javax.faces.ViewState"
FOFA: body="javax.faces.viewstate"
FOFA: body="javax.faces.resource"

Source: ProjectDiscovery

References

8