Vulnerability Description
A local file inclusion (LFI) vulnerability exists in version BIQS IT Biqs-drive v1.83 and below when sending a specific payload as the file parameter to download/index.php. This allows the attacker to read arbitrary files from the server with the permissions of the configured web-user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Biqs | Biqsdrive | <= 1.83 |
References
- https://biqs-drive.be/Broken Link
- https://github.com/PinkDraconian/CVE-2021-39433/blob/main/README.mdExploitThird Party Advisory
- https://biqs-drive.be/Broken Link
- https://github.com/PinkDraconian/CVE-2021-39433/blob/main/README.mdExploitThird Party Advisory
FAQ
What is CVE-2021-39433?
CVE-2021-39433 is a vulnerability with a CVSS score of 7.5 (HIGH). A local file inclusion (LFI) vulnerability exists in version BIQS IT Biqs-drive v1.83 and below when sending a specific payload as the file parameter to download/index.php. This allows the attacker to...
How severe is CVE-2021-39433?
CVE-2021-39433 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-39433?
Check the references section above for vendor advisories and patch information. Affected products include: Biqs Biqsdrive.