Loading HuntDB...

Path Traversal on meetcqpub1.gsa.gov allows attackers to see arbitrary file listings.

Low
U
U.S. General Services Administration
Submitted None
Reported by 0x0luke

Vulnerability Details

Technical details and impact analysis

Path Traversal
## Summary: Path Traversal on meetcqpub1.gsa.gov allows attackers to see arbitrary file listings from a directory of their choice. I wasn't sure if this page was in scope of this program or the TTS program, hopefully this isn't a problem ## Steps To Reproduce: 1. Navigate to the following URL - https://meetcqpub1.gsa.gov/bin/querybuilder.json.css?path=/home&p.hits=full&p.limit=-1 2. The path parameter can be manipulated to show other directories on the system as well, for example /etc. ## Impact An attacker is able to see files and directories present on the system, breaking the confidentiality section of the CIA Triad.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Path Traversal