Eibiz imedia server digital signage 3.8.0 configuration disclosure Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2020-08-24 |
Type : webapps |
Platform : hardware
This exploit / vulnerability Eibiz imedia server digital signage 3.8.0 configuration disclosure is for educational purposes only and if it is used you will do on your own risk!
Eibiz i-Media Server Digital Signage 3.8.0 Configuration Disclosure
Vendor: EIBIZ Co.,Ltd.
Product web page: http://www.eibiz.co.th
Affected version: <=3.8.0
Summary: EIBIZ develop advertising platform for out of home media in that
time the world called "Digital Signage". Because most business customers
still need get outside to get in touch which products and services. Online
media alone cannot serve them right place, right time.
Desc: i-Media Server is vulnerable to unauthenticated configuration disclosure
when direct object reference is made to the SiteConfig.properties file using an
HTTP GET method. This will enable the attacker to disclose sensitive information
and help her in authentication bypass, privilege escalation and/or full system access.
Tested on: Windows Server 2016
Windows Server 2012 R2
Windows Server 2008 R2
Apache Flex
Apache Tomcat/6.0.14
Apache-Coyote/1.1
BlazeDS Application
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience