Описание
ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITEWare Editor's Desktop or (2) the template parameter in SWEditServlet.
Ссылки
- Vendor Advisory
- Vendor Advisory
- US Government Resource
- ExploitPatchVendor Advisory
- Vendor Advisory
- Vendor Advisory
- US Government Resource
- ExploitPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.1 (включая)
cpe:2.3:a:screaming_media:siteware:*:*:*:*:*:*:*:*
EPSS
Процентиль: 96%
0.23603
Средний
10 Critical
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITEWare Editor's Desktop or (2) the template parameter in SWEditServlet.
EPSS
Процентиль: 96%
0.23603
Средний
10 Critical
CVSS2
Дефекты
NVD-CWE-Other