Описание
prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.
prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-3081
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93930
- http://packetstormsecurity.com/files/127543/IBM-1754-GCM-KVM-Code-Execution-File-Read-XSS.html
- http://seclists.org/fulldisclosure/2014/Jul/113
- http://www.exploit-db.com/exploits/34132
- http://www.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5095983
Связанные уязвимости
nvd
больше 11 лет назад
prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.