PT-2011-1770 · Oneorzero · Oneorzero Aims

Valentin Hoebel

·

Published

2011-09-13

·

Updated

2012-02-14

·

CVE-2010-4835

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions OneOrZero AIMS version 2.6.0 Members Edition
Description A directory traversal issue exists, allowing remote authenticated users to read arbitrary files. This is achieved through directory traversal sequences in the controller parameter in a show report action.
Recommendations For OneOrZero AIMS version 2.6.0 Members Edition, consider restricting access to the show report action until a patch is available. As a temporary workaround, limit the use of the controller parameter to prevent directory traversal sequences.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-4835

Affected Products

Oneorzero Aims