file-inclusion

2 articles
sort: new top best
clear filter
0 6/10

A Local File Inclusion (LFI) vulnerability was discovered in Apache Drill through improper handling of file paths in the query interface, allowing an attacker to read arbitrary files from the server by manipulating the dfs storage plugin configuration to access sensitive files like /etc/passwd.

Apache Drill HackerOne Jobert Abma Gujjuboy10x00 Shodan crt.sh
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details
0 7/10
vulnerability

A Local File Inclusion (LFI) vulnerability was discovered in Apigee portals where the SCSS @import directive could be abused to read arbitrary files on the server by referencing paths like /etc/shadow, with compilation errors exposing file contents. The vulnerability was patched by Google shortly after disclosure through their VRP.

Apigee Google Google VRP Drupal 7 healthapix.apigee.io sass-lang.com
offensi.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details