OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive files by exploiting directory listing functionality. Attackers can browse directories like /debug/ and /php/ to discover configuration files, database credentials, and system information.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XOpenbmcs
APPOpenbmcs2.4
Related vulnerabilities
OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permi...
OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate databas...
OpenBMCS 2.4 zawiera podatność CSRF, która pozwala atakującym na wykonanie działań z uprawnieniami administrat...
OpenBMCS 2.4 zawiera niezautentykowaną podatność SSRF, która pozwala ataczkującym obejść firewall i przeprowad...