CVE-2017-11165
CVE-2017-11165
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/143328/DataTaker-DT80-dEX-1.50.012-Sensitive-Configuration-Exposure.htmlunverifiedcve_referencewww.exploit-db.com/exploits/42313/unverifiedexploitdbwww.exploit-db.com/exploits/42313unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →