S4E just found a medium [ai] private ip disclosure detection scanner
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-39433 Scanner

CVE-2021-39433 scanner - Local File Inclusion (LFI) vulnerability in BIQS IT Biqs-drive

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-39433
7.5
CVSS

A local file inclusion (LFI) vulnerability exists in version BIQS IT Biqs-drive v1.83 and below when sending a specific payload as the file parameter to download/index.php. This allows the attacker to read arbitrary files from the server with the permissions of the configured web-user.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

BIQS IT Biqs-drive is a software used for file sharing and storage in businesses and organizations. It allows users to access and store files remotely, enabling hassle-free collaboration and seamless data management. The software offers several features such as file versioning, password protection, and file locking, which ensures secure data sharing and storage. 

However, recent security research has discovered a critical vulnerability in the system, designated as CVE-2021-39433. The local file inclusion (LFI) vulnerability in version BIQS IT Biqs-drive v1.83 and below is caused by a specific payload that is sent as the file parameter to download/index.php. This allows attackers to access and read arbitrary files from the server with permissions to the configured web-user account, enabling them to compromise the system and steal confidential information.

Exploitation of the vulnerability can result in a potential data breach and information leak that can cause severe reputational and financial damage to businesses and organizations. Attackers can gain access to sensitive data such as personal identifiable information, client data, and confidential business data, which can be used for identity theft, fraud, and other malicious activities.

Finally, with the pro feature of s4e.io, users can easily and quickly learn about vulnerabilities in their digital assets by subscribing to the platform. With detailed reports and insights on the latest vulnerabilities, users can take necessary precautions to prevent exploitation and ensure top-notch security for their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of BIQS IT Biqs-drive must take necessary precautions to prevent exploitation. Here are some best practices they can employ:

  • Update to the latest version of the software to fix the vulnerability.
  • Regularly monitor and review server logs for any suspicious requests or unauthorized access attempts.
  • Use web application firewalls (WAFs) to log and block malicious traffic.
  • Restrict server or file permissions, removing unnecessary read access to sensitive files.
  • Use authentication layers such as two-factor authentication, public and private key authentication to enhance security.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-39433 scanner - Local File Inclusion (LFI) vulnerability in BIQS IT Biqs-drive S4E