Description
This module exploits a directory traversal vulnerability in Ulterius Server < v1.9.5.0 to download files from the affected host. A valid file path is needed to download a file. Fortunately, Ulterius indexes every file on the system, which can be stored in the following location:
http://ulteriusURL:port/.../fileIndex.db.
This module can download and parse the fileIndex.db file. There is also an option to download a file using a provided path.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/admin/http/ulterius/file_downloadmsf undefined(file_download) > show actions ...actions...msf undefined(file_download) > set ACTION < action-name >msf undefined(file_download) > show options ...show and set options...msf undefined(file_download) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub