2021-08-02 16:17:48 +00:00
id : CVE-2020-27361
info :
name : Akkadian Provisioning Manager - Files Listing
author : gy741
severity : high
description : An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories.
2022-04-22 10:38:41 +00:00
reference :
- https://www.blacklanternsecurity.com/2021-07-01-Akkadian-CVE/
2021-09-10 11:26:40 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
2022-04-22 10:38:41 +00:00
cvss-score : 7.5
2021-09-10 11:26:40 +00:00
cve-id : CVE-2020-27361
cwe-id : CWE-668
2022-04-22 10:38:41 +00:00
tags : cve,cve2020,akkadian,listing,exposure
2021-08-02 16:17:48 +00:00
requests :
- method : GET
path :
- "{{BaseURL}}/pme/media/"
matchers-condition : and
matchers :
- type : word
words :
- "Index of /pme/media"
- "Parent Directory"
condition : and
- type : status
status :
- 200