Descripción
ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying paths used retrieve local resources. Attackers can manipulate parameters bypass controls and sensitive information including configuration files, source code, protected application
https://cxsecurity.com/issue/WLB-2016090001
https://exchange.xforce.ibmcloud.com/vulnerabilities/116489
https://packetstormsecurity.com/files/138570
https://www.exploit-db.com/exploits/40326/
https://www.vulncheck.com/advisories/zkteco-zkbiosecurity-file-path-manipulation-vulnerability
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5365.php