CVE-2021-4463
HIGH NUCLEILongjing Technology BEMS API <=1.21 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-4463. PoCs published by LiquidWorm. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated arbitrary file download vulnerability in Longjing Technology BEMS API 1.21 via directory traversal attacks. The PoC uses curl commands to retrieve sensitive files like /etc/passwd and /etc/shadow.
Description
Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.
Exploits (1)
This exploit demonstrates an unauthenticated arbitrary file download vulnerability in Longjing Technology BEMS API 1.21 via directory traversal attacks. The PoC uses curl commands to retrieve sensitive files like /etc/passwd and /etc/shadow.
Nuclei Templates (1)
References (7)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N