PT-2009-2553 · Velocity · Velocity Security Management System
Published
2009-08-26
·
Updated
2018-10-11
·
CVE-2008-7084
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Velocity Security Management System version 1.0
Description
A directory traversal issue in the web server allows remote attackers to read arbitrary files by including a .. (dot dot) in the URI.
Recommendations
For version 1.0, update the web server to prevent directory traversal attacks, ensuring that input validation and sanitization are properly implemented to prevent access to arbitrary files.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Velocity Security Management System