PT-2018-9694 · Qingdao Nature Easy Soft · Qingdao Nature Easy Soft Chanzhi Enterprise Portal System
Tom0Li
·
Published
2018-04-16
·
Updated
2018-05-23
·
CVE-2018-10122
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
QingDao Nature Easy Soft Chanzhi Enterprise Portal System (aka chanzhieps) version pro1.6
Description:
The issue allows remote attackers to read arbitrary files via directory traversal sequences in the
pathname parameter to "www/file.php" API endpoint.Recommendations:
For version pro1.6, restrict access to the "www/file.php" endpoint to minimize the risk of exploitation, and avoid using the
pathname parameter until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qingdao Nature Easy Soft Chanzhi Enterprise Portal System