PT-2000-1568 · Stalker · Communigate Pro
Published
2000-04-03
·
Updated
2017-10-10
·
CVE-2000-0634
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CommuniGate Pro versions 3.2.5 and earlier
Description
The issue allows remote attackers to read arbitrary files via a .. (dot dot) attack, which is due to CommuniGate Pro not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the URI.
Recommendations
For CommuniGate Pro versions 3.2.5 and earlier, consider restricting access to the web administration interface until a fix is available, and avoid using URI inputs that could facilitate traversal style attacks.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Communigate Pro