mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 01:31:01 +00:00
24 lines
1.0 KiB
Markdown
24 lines
1.0 KiB
Markdown
![]() |
### [CVE-2017-14537](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14537)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- http://packetstormsecurity.com/files/162853/Trixbox-2.8.0.4-Path-Traversal.html
|
||
|
- https://secur1tyadvisory.wordpress.com/2018/02/13/trixbox-multiple-path-traversal-vulnerabilities-cve-2017-14537/
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/ARPSyndicate/kenzer-templates
|
||
|
- https://github.com/Elsfa7-110/kenzer-templates
|
||
|
- https://github.com/Hacker5preme/Exploits
|
||
|
- https://github.com/merlinepedra/nuclei-templates
|
||
|
- https://github.com/merlinepedra25/nuclei-templates
|
||
|
- https://github.com/sobinge/nuclei-templates
|
||
|
|