HomePentest-Tools.com Logo

Aptana Jaxer 1.0.3.4547 - Local File inclusion CVE-2019-14312

Severity
CVSSv3 Score
6.5
Vulnerability description

Aptana Jaxer 1.0.3.4547 is vulnerable to local file inclusion in the wikilite source code viewer. An attacker can read internal files on the server via a tools/sourceViewer/index.html?filename=../ URI.

Risk description

The risk exists that a remote unauthenticated attacker could exploit this vulnerability to read sensitive information from arbitrary files located on the file system of the server.

Recommendation

Upgrade to a patched version of Aptana Jaxer or apply the necessary security patches to mitigate the LFI vulnerability.

Codename
Not available
Detectable with
Network Scanner
Scan engine
Nuclei
Exploitable with Sniper
No
CVE Published
Aug 9, 2019
Detection added at
Software Type
Not available
Vendor
Not available
Product
Not available