Path traversal in dnaLIMS - CVE-2017-6527

 

Path traversal in dnaLIMS - CVE-2017-6527

Published: March 9, 2017 / Updated: August 9, 2020


Vulnerability identifier: #VU39478
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6527
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticated attacker to access system files readable by the web server user (by using the viewAppletFsa.cgi seqID parameter).


Affected software

dnaLIMS

How to mitigate CVE-2017-6527

Install update from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins