HTTP: Laravel Log Viewer Local File Download

This signature detects attempts to exploit a known vulnerability against Laravel Log Viewer. A successful attack can lead to Local File Download.

Extended Description

rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.

Affected Products

Laravel_log_viewer_project laravel_log_viewer

Short Name
HTTP:PHP:LARAVEL-LOG-LFD
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2018-8947 Download File Laravel Local Log Viewer
Release Date
09/17/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Laravel_log_viewer_project

CVSS Score

5.0

Found a potential security threat?