CVE-2021-34805
FAUST iServer 9.0.018.018.4 - Local File Inclusion
Record summary
CVE-2021-34805 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHFAUST iServer 9.0.018.018.4 - Local File InclusionCVSS 7.5
FAUST iServer before 9.0.019.019.7 is susceptible to local file inclusion because for each URL request it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.
Impact
Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the server.
Remediation
Apply the latest security patch or update to a non-vulnerable version of FAUST iServer.
Source: ProjectDiscovery