PT-2009-2553 · Velocity · Velocity Security Management System
Publicado
2009-08-26
·
Atualizado
2018-10-11
·
CVE-2008-7084
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Velocity Security Management System version 1.0
Description
A directory traversal issue in the web server allows remote attackers to read arbitrary files by including a .. (dot dot) in the URI.
Recommendations
For version 1.0, update the web server to prevent directory traversal attacks, ensuring that input validation and sanitization are properly implemented to prevent access to arbitrary files.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Velocity Security Management System