2024-05-25 21:48:12 +02:00
### [CVE-2021-34805](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34805)

2025-09-29 21:09:30 +02:00


2024-05-25 21:48:12 +02:00
### Description
An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.
### POC
#### Reference
- http://packetstormsecurity.com/files/165701/FAUST-iServer-9.0.018.018.4-Local-File-Inclusion.html
- https://sec-consult.com/vulnerability-lab/
#### Github
- https://github.com/20142995/Goby
2025-09-29 21:09:30 +02:00
- https://github.com/20142995/nuclei-templates
2024-05-25 21:48:12 +02:00
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/HimmelAward/Goby_POC
2025-09-29 21:09:30 +02:00
- https://github.com/NyxAzrael/Goby_POC
2024-05-25 21:48:12 +02:00
- https://github.com/Z0fhack/Goby_POC