Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-11798 PoC — Mitel Networks MiCollab AWV 路径遍历漏洞

Source
Associated Vulnerability
Title:Mitel Networks MiCollab AWV 路径遍历漏洞 (CVE-2020-11798)
Description:Mitel Networks MiCollab AWV是加拿大Mitel Networks公司的一款用于管理音频、网络和视频会议的应用程序。 Mitel Networks MiCollab AWV 8.1.2.4之前版本和9.1.3之前的9.x版本中的web conference组件存在路径遍历漏洞,该漏洞源于程序没有充分验证访问权限。攻击者可借助特制URL利用该漏洞访问服务器受限目录上的任意文件。
Description
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.
File Snapshot

id: CVE-2020-11798 info: name: Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal autho ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.