V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2019-13063
CVE
HighConfirmedExploit available

Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on t…

CVSS
7.5
High
EPSS
0.27
p97
Published
2019-01-01
Updated
2019-01-01
Description

Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_view page. This will result in file disclosure (i.e., being able to pull any file from the remote victim application). This can be used to steal and obtain sensitive config and other files. This can result in complete compromise of the application. The script parameter is vulnerable to directory traversal and both local and remote file inclusion.

Tags · CWE
Pre-auth
CWE-22
CAPEC-64
CAPEC-76
CAPEC-78
CAPEC-79
CAPEC-126
Affected products
Sahi_pro
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.272 · p97
Known exploited (KEV)
No
Known exploits — Сканер-ВС
47062
exploitdb · https://www.exploit-db.com/exploits/47062
Enterprise
CVE-2019-13063
github-poc · https://github.com/0x6b7966/CVE-2019-13063-POC
Enterprise
Affected products
ProductVendorStatus
sahi_pro*Tracked
Source databases
CVE