cve/2023/CVE-2023-25804.md
2024-05-25 21:48:12 +02:00

912 B

CVE-2023-25804

Description

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a limited path traversal vulnerability. An SSH key can be saved into an unintended location, for example the /tmp folder using a payload ../../../../../tmp/test111_dev. This issue has been fixed in version 6.3.5.0.

POC

Reference

No PoCs from references.

Github