PT-2015-5584 · Ectouch · Etouch Samepage Enterprise Edition
Brandon Perry
·
Published
2015-02-24
·
Updated
2016-11-30
·
CVE-2015-2071
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
eTouch SamePage Enterprise Edition version 4.4.0.0.239
Description
A directory traversal issue exists, allowing remote authenticated users to read arbitrary files. This is achieved by using a .. (dot dot) in the
filepath parameter of the /cm/newui/blog/export.jsp API endpoint.Recommendations
For version 4.4.0.0.239, as a temporary workaround, consider restricting access to the /cm/newui/blog/export.jsp endpoint until a patch is available. Avoid using the
filepath parameter with unvalidated input to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Etouch Samepage Enterprise Edition