CVE-2023-31059
HIGH EXPLOITED NUCLEIRepetier Server <1.4.10 - Path Traversal
Title source: llmExploitation Summary
CVE-2023-31059 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including mbanyamer. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2023-31059, an unauthenticated path traversal vulnerability in Repetier-Server ≤ 1.4.10. The exploit leverages improper sanitization of Windows backslash sequences (..%5c) to read arbitrary files via the connectionLost.php endpoint.
Description
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php.
Exploits (1)
This repository contains a functional Python exploit for CVE-2023-31059, an unauthenticated path traversal vulnerability in Repetier-Server ≤ 1.4.10. The exploit leverages improper sanitization of Windows backslash sequences (..%5c) to read arbitrary files via the connectionLost.php endpoint.
Nuclei Templates (1)
title:"Repetier-Server" || http.title:"repetier-server"
title="Repetier-Server" || title="repetier-server"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N