CVE-2017-7258
Last modified
CVE-2017-7258 is a vulnerability of currently unknown severity. HTTP Exploit in eMLi Portal in AuroMeera Technometrix Pvt. Ltd. EPSS estimates a 2.25% chance of exploitation in the next 30 days.
Description
HTTP Exploit in eMLi Portal in AuroMeera Technometrix Pvt. Ltd. eMLi allows an Attacker to View Restricted Information or (even more seriously) execute powerful commands on the web server which can lead to a full compromise of the system via Directory Path Traversal, as demonstrated by reading core-emli/Storage. The affected versions are eMLi School Management 1.0, eMLi College Campus Management 1.0, and eMLi University Management 1.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Auromeera | Emli | 1.0 |
References
- http://www.securityfocus.com/bid/97255Third Party Advisory, VDB Entry
- https://sudoat.blogspot.in/2017/03/path-traversal-vulnerability-in-emli.htmlThird Party Advisory
- http://www.securityfocus.com/bid/97255Third Party Advisory, VDB Entry
- https://sudoat.blogspot.in/2017/03/path-traversal-vulnerability-in-emli.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7258?
How severe is CVE-2017-7258?
How do I fix CVE-2017-7258?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7251A Cross-Site Scripting (XSS) was discovered in pi-engine/pi …6.1
- CVE-2017-7252bcrypt password hashing in Botan before 2.1.0 does not corre…7.5
- CVE-2017-7253Dahua IP Camera devices 3.200.0001.6 can be exploited via th…
- CVE-2017-7255XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->N…
- CVE-2017-7256XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->N…
- CVE-2017-7257XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->N…
- CVE-2017-7259Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-7261The vmw_surface_define_ioctl function in drivers/gpu/drm/vmw…
- CVE-2017-7262The AMD Ryzen processor with AGESA microcode through 2017-01…
- CVE-2017-7263The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 …
- CVE-2017-7264Use-after-free vulnerability in the fz_subsample_pixmap func…5.3
- CVE-2017-7266Netflix Security Monkey before 0.8.0 has an Open Redirect. T…
Are you affected by CVE-2017-7258?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
