Description
OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive files by exploiting directory listing functionality. Attackers can browse directories like /debug/ and /php/ to discover configuration files, database credentials, and system information.
Problem types
CWE-548 Exposure of Information Through Directory Listing
Product status
2.4
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/50671 (ExploitDB-50671)
www.openbmcs.com (Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5695.php (Zero Science Lab Disclosure (ZSL-2022-5695))
www.vulncheck.com/...irectory-listing-information-disclosure (VulnCheck Advisory: OpenBMCS Directory Listing Information Disclosure)