PT-2017-4227 · Boa · Boa

Miguel Mendez Z

·

Publicado

2017-06-20

·

Atualizado

2024-08-05

·

CVE-2017-9833

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Boa version 0.94.14rc21
Description The issue is related to the /cgi-bin/wapopen script in the Boa HTTP server, which is vulnerable to path traversal attacks using the FILECAMERA variable sent via GET requests. This could allow a remote attacker to gain unauthorized access to protected information by sending specially crafted requests. It is noted that this might be a system-integrator issue rather than a vulnerability in Boa itself, as Boa does not include any wapopen program or code to read the FILECAMERA variable.
Recommendations For Boa version 0.94.14rc21, consider disabling the /cgi-bin/wapopen script until a patch is available, or restrict access to this script to minimize the risk of exploitation. Additionally, avoid using the FILECAMERA variable in the affected API endpoint until the issue is resolved.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-07373
CVE-2017-9833

Produtos afetados

Boa