PT-2016-4412 · Apache · Apache Openmeetings

Andreas Lindh

·

Publicado

2016-04-11

·

Atualizado

2022-05-14

·

CVE-2016-0784

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache OpenMeetings versions prior to 3.1.1
Description The issue concerns a directory traversal vulnerability in the Import/Export System Backups functionality. This allows remote authenticated administrators to write to arbitrary files by including a .. (dot dot) in a ZIP archive entry.
Recommendations For versions prior to 3.1.1, update to version 3.1.1 or later to resolve the issue.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-0784
GHSA-8XQ7-7HCX-8P8G

Produtos afetados

Apache Openmeetings