PT-2015-6035 · Neojapan · Neojapan Desknet Neo
Hiroyuki Yamashita
·
Publicado
2015-09-05
·
Atualizado
2015-09-11
·
CVE-2015-2990
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NEOJAPAN desknet NEO versions 2.0R1.0 through 2.5R1.4
Description
A directory traversal issue exists in zhtml.cgi, allowing remote authenticated users to read arbitrary files by providing a crafted parameter.
Recommendations
For versions 2.0R1.0 through 2.5R1.4, consider restricting access to the zhtml.cgi script until a fix is available. As a temporary workaround, avoid using crafted parameters that could exploit the directory traversal issue in zhtml.cgi.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Neojapan Desknet Neo