.. / CVE-2019-12276

Exploit for GrandNode 4.40 - Local File Inclusion (CVE-2019-12276)

Description:

GrandNode 4.40 is susceptible to local file inclusion in Controllers/LetsEncryptController.cs, which allows remote unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests.

Nuclei Template

View the template here CVE-2019-12276.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-12276.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2019-12276
https://grandnode.com
https://security401.com/grandnode-path-traversal/
http://packetstormsecurity.com/files/153373/GrandNode-4.40-Path-Traversal-File-Download.html
https://github.com/grandnode/grandnode