Update CVE-2024-33113.yaml

patch-4
Dhiyaneshwaran 2024-07-04 16:28:19 +05:30 committed by GitHub
parent 71778be115
commit 71de94bec1
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 8 additions and 2 deletions

View File

@ -5,12 +5,18 @@ info:
author: pussycat0x
severity: medium
description: |
CVE-2024-33113 is a vulnerability in the D-LINK DIR-845L router that allows information disclosure through the bsc_sms_inbox.php file. The vulnerability arises from improper handling of the include() function, which can be exploited by manipulating the $file variable. This allows attackers to include arbitrary PHP scripts and potentially retrieve sensitive information such as the router's username and password.
D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
reference:
- https://github.com/FaLLenSKiLL1/CVE-2024-33113
- https://github.com/yj94/Yj_learning/blob/main/Week16/D-LINK-POC.md
- https://github.com/yj94/Yj_learning
- https://github.com/fkie-cad/nvd-json-data-feeds
classification:
epss-score: 0.00043
epss-percentile: 0.0866
metadata:
max-request: 1
verified: true
max-request: 1
shodan-query: DIR-845L
tags: cve,cve2024,dlink