PT-2011-1770 · Oneorzero · Oneorzero Aims
Valentin Hoebel
·
Published
2011-09-13
·
Updated
2012-02-14
·
CVE-2010-4835
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OneOrZero AIMS version 2.6.0 Members Edition
Description
A directory traversal issue exists, allowing remote authenticated users to read arbitrary files. This is achieved through directory traversal sequences in the
controller parameter in a show report action.Recommendations
For OneOrZero AIMS version 2.6.0 Members Edition, consider restricting access to the
show report action until a patch is available. As a temporary workaround, limit the use of the controller parameter to prevent directory traversal sequences.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oneorzero Aims