AnyShare Cloud 6.0.9 allows authenticated directory traversal to read files, as demonstrated by the interface/downloadwithpath/downloadfile/?filepath=/etc/passwd URI.
References
Link Resource
https://github.com/codingdream/anyshare_vul Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-02-16T17:06:20

Updated: 2020-02-16T17:06:20

Reserved: 2020-02-16T00:00:00


Link: CVE-2020-8996

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-02-16T18:15:10.890

Modified: 2020-02-21T17:17:20.420


Link: CVE-2020-8996

JSON object: View

cve-icon Redhat Information

No data.

CWE