Path traversal in lanproxy - CVE-2021-3019
Published: January 5, 2021 / Updated: September 18, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted URL request containing "dot dot" sequences (/../) to access conf/config.properties on the system.
Affected software
How to mitigate CVE-2021-3019
Links to Public Exploits and PoC-codes
- Exploit #9340 - CVE-2021-3019 (lanproxy 目录遍历漏洞批量检测用户名密码POC (CVE-2021-3019)) (September 18, 2023)
- Exploit #7530 - CVE-2021-3019 (CVE-2021-3019 lanproxy目录遍历任意文件读取漏洞探测POC) (March 23, 2022)
- Exploit #6936 - CVE-2021-3019 () (October 24, 2021)
- Exploit #6705 - CVE-2021-3019-Lanproxy () (September 5, 2021)
- Exploit #6641 - CVE-2021-3019 ([CVE-2021-3019] LanProxy Directory Traversal) (August 19, 2021)
- Exploit #6542 - CVE-2021-3019 (lanproxy 目录遍历漏洞批量检测 (CVE-2021-3019)) (July 19, 2021)
- Exploit #5481 - CVE-2021-3019 (lanproxy 目录遍历漏洞批量检测用户名密码POC (CVE-2021-3019)) (May 25, 2021)
- Exploit #5021 - CVE-2021-3019 (CVE-2021-3019 lanproxy目录遍历任意文件读取漏洞探测POC) (January 11, 2021)