PT-2022-10165 · Agg · Agg Software Web Server
Michael Heinzl
·
Published
2022-05-24
·
Updated
2023-07-07
·
CVE-2021-32964
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AGG Software Web Server versions 4.0.40.1014 and prior
Description
The issue allows an attacker to perform a path traversal attack, potentially enabling them to read arbitrary files from the file system.
Recommendations
For AGG Software Web Server versions 4.0.40.1014 and prior, consider restricting access to sensitive files and directories until a patch is available. As a temporary workaround, limit the web server's ability to access arbitrary files from the file system. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Agg Software Web Server