PT-2007-2325 · Ip3 · Ip3 Netaccess
Sebastian Wolfgarten
·
Published
2007-02-12
·
Updated
2018-10-16
·
CVE-2007-0883
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
IP3 NetAccess versions prior to 4.1.9.6
Description:
The issue allows remote attackers to read arbitrary files via a .. (dot dot) in the
filename parameter in the portalgroups/portalgroups/getfile.cgi endpoint.Recommendations:
For versions prior to 4.1.9.6, update to firmware version 4.1.9.6 to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ip3 Netaccess