CVE-2021-38146 Scanner
Targets the `/home/download` endpoint via the `SearchString` JSON parameter, enabling an attacker to download arbitrary files from the server.
Used 3.1k times · 5.9k assets checked · url
The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary files via absolute path traversal in the SearchString JSON field in /home/download POST data.
Targets the `/home/download` endpoint via the `SearchString` JSON parameter, enabling an attacker to download arbitrary files from the server.
Used 3.1k times · 5.9k assets checked · url
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →