PT-2017-16794 · Sitecore · Sitecore Cms

Publicado

2017-05-23

·

Atualizado

2017-06-08

·

CVE-2017-5966

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sitecore CRM version 8.1 Rev 151207
Description The issue allows remote authenticated administrators to read arbitrary files via an absolute path traversal attack. This is achieved by exploiting the file parameter in the "sitecore/shell/download.aspx" API endpoint.
Recommendations For Sitecore CRM version 8.1 Rev 151207, consider restricting access to the sitecore/shell/download.aspx endpoint to prevent absolute path traversal attacks, and avoid using the file parameter until a fix is available.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-5966

Produtos afetados

Sitecore Cms