CVE-2016-4314
CVE-2016-4314
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/138330/WSO2-Carbon-4.4.5-Local-File-Inclusion.htmlunverifiedcve_referencewww.exploit-db.com/exploits/40240/unverifiedexploitdbwww.exploit-db.com/exploits/40240unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://hyp3rlinx.altervista.org/advisories/WSO2-CARBON-v4.4.5-LOCAL-FILE-INCLUSION.txthttp://packetstormsecurity.com/files/138330/WSO2-Carbon-4.4.5-Local-File-Inclusion.htmlhttps://docs.wso2.com/display/Security/Security+Advisory+WSO2-2016-0098https://www.exploit-db.com/exploits/40240/http://www.securityfocus.com/archive/1/539200/100/0/threadedhttp://www.securityfocus.com/bid/92473