github.com
https://github.com/kekingcn/kkFileView/issues/304 CVE-2021-43734
HIGHNuclei
kkFileview v4.0.0 - Local File Inclusion
Record summary
CVE-2021-43734 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHkkFileview v4.0.0 - Local File InclusionCVSS 7.5
kkFileview v4.0.0 is vulnerable to local file inclusion which may lead to a sensitive file leak on a related host.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire system.
Remediation
Upgrade to a patched version of kkFileview v4.0.1 or later, or apply the necessary security patches provided by the vendor.
WeaknessesCWE-22
Authorsarafatansari
Template tagscve2021cvekkfileviewtraversallfikekingvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:keking:kkfileview:4.0.0:*:*:*:*:*:*:*
Shodan: http.html:"kkFileView"
Shodan: http.html:"kkfileview"
FOFA: body="kkfileview"
FOFA: app="kkfileview"
https://github.com/kekingcn/kkFileView/issues/304 https://nvd.nist.gov/vuln/detail/CVE-2021-43734 https://github.com/20142995/Goby https://github.com/ARPSyndicate/kenzer-templates https://github.com/ArrestX/--POC
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-43734