mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-31 10:40:54 +00:00
740 B
740 B
CVE-2022-29596
Description
MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=any_password&ConnMode=1&3054=Login substring for directory traversal.
POC
Reference
Github
No PoCs found on GitHub currently.