Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-58310. PoCs published by Víctor García.
AI-analyzed exploit summary This exploit demonstrates a path traversal vulnerability in the UPS Network Management Card 4, allowing unauthorized access to sensitive files such as /etc/passwd. The PoC uses a curl command with URL-encoded traversal sequences to bypass directory restrictions.
Description
APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like /etc/passwd by using encoded path traversal characters in HTTP requests.
Exploits (1)
This exploit demonstrates a path traversal vulnerability in the UPS Network Management Card 4, allowing unauthorized access to sensitive files such as /etc/passwd. The PoC uses a curl command with URL-encoded traversal sequences to bypass directory restrictions.
References (3)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N