Medium severity5.3NVD Advisory· Published Jun 13, 2022· Updated Jun 17, 2026
CVE-2022-23167
CVE-2022-23167
Description
Attacker crafts a GET request to: /mobile/downloadfile.aspx? Filename =../.. /windows/boot.ini the LFI is UNAUTHENTICATED.
Affected products
2Patches
Vulnerability mechanics
References
1- www.gov.il/en/departments/faq/cve_advisoriesnvdThird Party Advisory
News mentions
0No linked articles in our index yet.