CVE-2017-12761
UnknownEPSS 2.53%
Last modified
CVE-2017-12761 is a vulnerability of currently unknown severity. http://codecanyon.net/user/Endober WebFile Explorer 1.0 is affected by: SQL Injection. The impact is: Arbitrary File Download (remote). EPSS estimates a 2.53% chance of exploitation in the next 30 days.
Description
http://codecanyon.net/user/Endober WebFile Explorer 1.0 is affected by: SQL Injection. The impact is: Arbitrary File Download (remote). The component is: $file = $_GET['id'] in download.php. The attack vector is: http://speicher.example.com/envato/codecanyon/demo/web-file-explorer/download.php?id=WebExplorer/../config.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Webfile Explorer Project | Webfile Explorer | 1.0 |
References
- http://codecanyon.net/user/EndoberNot Applicable, Third Party Advisory
- http://speicher.example.com/envato/codecanyon/demo/web-file-explorer/download.php?id=WebExplorer/../config.phpBroken Link, Third Party Advisory
- http://webfile.comThird Party Advisory
- https://www.exploit-db.com/exploits/42440Exploit, Third Party Advisory, VDB Entry
- http://codecanyon.net/user/EndoberNot Applicable, Third Party Advisory
- http://speicher.example.com/envato/codecanyon/demo/web-file-explorer/download.php?id=WebExplorer/../config.phpBroken Link, Third Party Advisory
- http://webfile.comThird Party Advisory
- https://www.exploit-db.com/exploits/42440Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12761?
http://codecanyon.net/user/Endober WebFile Explorer 1.0 is affected by: SQL Injection. The impact is: Arbitrary File Download (remote). The component is: $file = $_GET['id'] in download.php. The attack vector is: http://speicher.example.com/envato/codecanyon/demo/web-file-explorer/download.php?id=WebExplorer/../config.php.
How severe is CVE-2017-12761?
Severity scoring for CVE-2017-12761 is pending analysis. The EPSS model estimates a 2.53% probability of exploitation in the next 30 days.
How do I fix CVE-2017-12761?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2017-12761?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
