CVE-2018-11344: Path Traversal
A path traversal vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify a file on the system to download via the file1 parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11344?
CVE-2018-11344 is a path traversal vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3, which allows attackers to specify a file on the system to download via the file1 parameter.
How does CVE-2018-11344 affect ASUSTOR AS6202T ADM 3.1.0.RFQ3?
CVE-2018-11344 affects ASUSTOR AS6202T ADM 3.1.0.RFQ3 by enabling attackers to arbitrarily specify a file on the system to download.
What is the severity of CVE-2018-11344?
The severity of CVE-2018-11344 is medium, with a CVSS score of 6.5.
How can I fix CVE-2018-11344?
To fix CVE-2018-11344, upgrade to a version of ASUSTOR AS6202T ADM that includes a patch for the vulnerability.
Where can I find more information about CVE-2018-11344?
More information about CVE-2018-11344 can be found on the following references: - http://seclists.org/fulldisclosure/2018/May/2 - https://github.com/mefulton/asustorexploit - https://www.purehacking.com/blog/matthew-fulton/back-to-the-future-asustor-web-exploitation