.. / CVE-2015-3897

Exploit for Bonita BPM Portal <6.5.3 - Local File Inclusion (CVE-2015-3897)

Description:

Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the theme parameter and a file path in the location parameter to bonita/portal/themeResource.

Nuclei Template

View the template here CVE-2015-3897.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2015/CVE-2015-3897.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2015-3897
https://packetstormsecurity.com/files/132237/Bonita-BPM-6.5.1-Directory-Traversal-Open-Redirect.html
https://www.htbridge.com/advisory/HTB23259
https://github.com/ARPSyndicate/kenzer-templates
https://www.bonitasoft.com/