CyberRota Analysis
AI-GeneratedTobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion flaw that allows authenticated users to bypass existing filters and download sensitive files, including other users' access files and the server's private key, by manipulating the '@@attach' command in the 'scjob' form field. This high-severity vulnerability poses a significant risk to user data confidentiality and server integrity. Organizations using TeamDavid versions up to Rollout 524 should prioritize remediation to protect against potential data breaches.
Original NVD Description
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a message, which can then be downloaded by an authenticated user. A filter is in place that restricts access to the David con-fig folder and the user folder. However, this filter can be bypassed by specifying an alternate data stream, allowing the download of sensitive files such as other users' access files containing their passwords or the server's private key. This issue affects TeamDavid through Rollout 524.