Skip to content

Instantly share code, notes, and snippets.

@Stick-U235
Last active April 19, 2020 15:05
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save Stick-U235/b187931f828e92866d09b9bdeb956ca2 to your computer and use it in GitHub Desktop.
Save Stick-U235/b187931f828e92866d09b9bdeb956ca2 to your computer and use it in GitHub Desktop.
CVE-2017-6564 and CVE-2017-6565
>> [Suggested description]
>> On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices,
>> the Guest user, which contains the lowest privileges, can post to the
>> idSourceFileName parameter found within the /download directory. This
>> ability allows for an attacker to download sensitive system files from
>> the host machine such as databases which contain information that can
>> aid in further attacks.
> CVE-2017-6564.
>> [Suggested description]
>> On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices,
>> the roleDiag user, which can be obtained by exploiting CVE-2013-7247,
>> has the ability to upload files to the server hosting the web service.
>> As no sanitization checks are in place, an attacker can upload a
>> malicious payload.
> CVE-2017-6565.
- Stick
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment