.. / CVE-2018-16716

Exploit for NCBI ToolBox - Directory Traversal (CVE-2018-16716)

Description:

NCBI ToolBox 2.0.7 through 2.2.26 legacy versions contain a path traversal vulnerability via viewcgi.cgi which may result in reading of arbitrary files (i.e., significant information disclosure) or file deletion via the nph-viewgif.cgi query string.

Nuclei Template

View the template here CVE-2018-16716.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2018/CVE-2018-16716.yaml
Copy

References:

https://github.com/grymer/CVE
https://github.com/grymer/CVE/blob/master/CVE-2018-16716.md
https://github.com/ARPSyndicate/kenzer-templates
https://nvd.nist.gov/vuln/detail/CVE-2018-16716