CVE-2022-23347

HIGH EXPLOITED NUCLEI

BigAnt Server 5.6.06 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-23347 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.

Nuclei Templates (1)

BigAnt Server v5.6.06 - Local File Inclusion
HIGHVERIFIEDby 0x_Akoko
Shodan: http.html:"BigAnt" || http.html:"bigant"
FOFA: body="bigant"

References (3)

Core 3
Core References
Not Applicable, Product x_refsource_misc
http://bigant.com
Vendor Advisory x_refsource_misc
https://www.bigantsoft.com/

Scores

CVSS v3 7.5
EPSS 0.1312
EPSS Percentile 95.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2023-11-13
CWE
CWE-22
Status published
Products (1)
bigantsoft/bigant_server 5.6.06
Published Mar 21, 2022
Tracked Since Feb 18, 2026