CVE-2017-7258 Information
Feb 14, 2021
cve
Description
HTTP Exploit in eMLi Portal in AuroMeera Technometrix Pvt. Ltd. eMLi allows an Attacker to View Restricted Information or (even more seriously) execute powerful commands on the web server which can lead to a full compromise of the system via Directory Path Traversal as demonstrated by reading core-emli/Storage. The affected versions are eMLi School Management 1.0 eMLi College Campus Management 1.0 and eMLi University Management 1.0.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
http://www.securityfocus.com/bid/97255 https://sudoat.blogspot.in/2017/03/path-traversal-vulnerability-in-emli.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: