DoliWamp jqueryFileTree.php...

- AV AC AU C I A
发布: 2024-08-31
修订: 2025-04-13

This Metasploit module will extract user credentials from DoliWamp - a WAMP packaged installer distribution for Dolibarr ERP on Windows - versions 3.3.0 to 3.4.2 by hijacking a users session. DoliWamp stores session tokens in filenames in the tmp directory. A directory traversal vulnerability in jqueryFileTree.php allows unauthenticated users to retrieve session tokens by listing the contents of this directory. Note: All tokens expire after 30 minutes of inactivity by default.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息