github.com
https://github.com/rootd4ddy/CVE-2023-34843 CVE-2023-34843
HIGHNuclei
Traggo Server - Local File Inclusion
Record summary
CVE-2023-34843 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.
Description source: CVE List
Exploitation context
Proofs of concept
1Repository PoCs
GitHubrootd4ddy/CVE-2023-34843Repository PoCby rootd4ddyStars: 8Not analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHTraggo Server - Local File InclusionCVSS 7.5
traggo/server version 0.3.0 is vulnerable to directory traversal.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the server.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
WeaknessesCWE-22
AuthorsDhiyaneshDk
Template tagscve2023cvetraggolfiservervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:traggo:traggo:0.3.0:*:*:*:*:*:*:*
Shodan: html:"traggo"
Shodan: http.html:"traggo"
FOFA: body="traggo"
https://github.com/rootd4ddy/CVE-2023-34843 https://github.com/0x783kb/Security-operation-book https://github.com/Imahian/CVE-2023-34843 https://github.com/hheeyywweellccoommee/CVE-2023-34843-illrj https://github.com/nomi-sec/PoC-in-GitHub
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-34843