An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The ASP.net SMS module can be used to read and validate the source code of ASP files. By altering the path, it can be made to read any file on the Operating System, usually with NT AUTHORITY\SYSTEM privileges.
References
Configurations
History
21 Nov 2024, 05:02
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-14021-Arbitrary%20File%20Read-Ozeki%20SMS%20Gateway - Exploit, Third Party Advisory | |
References | () https://www.ozeki.hu/index.php?ow_page_number=1017&downloadaction=email&download_product_id=1&os=windows&dpath=%2Fattachments%2F702%2Finstallwindows_1590575794_OzekiNG-SMS-Gateway_4.17.6.zip&dname=Ozeki+NG+SMS+Gateway+v4.17.6&dsize=+%2817.8+MB%29&platform=Windows - Release Notes, Vendor Advisory | |
References | () https://www.ozeki.hu/index.php?owpn=231 - Vendor Advisory |
Information
Published : 2020-09-18 18:15
Updated : 2024-11-21 05:02
NVD link : CVE-2020-14021
Mitre link : CVE-2020-14021
CVE.ORG link : CVE-2020-14021
JSON object : View
Products Affected
ozeki
- ozeki_ng_sms_gateway
CWE