Record summary

CVE-2021-34805 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHFAUST iServer 9.0.018.018.4 - Local File InclusionCVSS 7.5

FAUST iServer before 9.0.019.019.7 is susceptible to local file inclusion because for each URL request it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.

Impact

Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the server.

Remediation

Apply the latest security patch or update to a non-vulnerable version of FAUST iServer.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2021cvelfipacketstormfaustiserverland-softwarevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:land-software:faust_iserver:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4