Exploits / Vulnerability Discovered : 2020-10-28 |
Type : webapps |
Platform : linux
This exploit / vulnerability Oracle business intelligence enterprise edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 getpreviewimage directory traversal/local file inclusion is for educational purposes only and if it is used you will do on your own risk!
# Description
A Directory Traversal vulnerability has been discovered in the 'getPreviewImage' function of Oracle Business Intelligence Enterprise Edition. The 'getPreviewImage' function is used to get a preview image of a previously uploaded theme logo. By manipulating the 'previewFilePath' URL parameter an attacker with access to the administration interface is able to read arbitrary system files.