CVE-2021-35250
Directory Transversal Vulnerability in Serv-U 15.3
Record summary
CVE-2021-35250 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List, VulnCheck | 15.3 only to < 15.3 Hotfix 1 | affected |
Proofs of concept
1Repository PoCs
GitHubrissor41/SolarWinds-CVE-2021-35250Repository PoCby rissor41Stars: 9Not analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHSolarWinds Serv-U 15.3 - Directory TraversalCVSS 7.5
SolarWinds Serv-U 15.3 is susceptible to local file inclusion, which may allow an attacker access to installation and server files and also make it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability could lead to unauthorized access to sensitive files, potentially exposing sensitive information or allowing for further attacks.
Remediation
Resolved in Serv-U 15.3 Hotfix 1.
Source: ProjectDiscovery