Описание
Directory traversal vulnerability in the web interface (ISALogin.dll) for TAC Vista 4.0, and possibly other versions before 4.3, allows remote attackers to read arbitrary files via ".." sequences in the Template parameter.
Ссылки
- Vendor Advisory
- ExploitVendor Advisory
- ExploitVendor Advisory
- Exploit
- Vendor Advisory
- ExploitVendor Advisory
- ExploitVendor Advisory
- Exploit
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:tac:vista:3.0:*:*:*:*:*:*:*
cpe:2.3:a:tac:vista:4.0:*:*:*:*:*:*:*
EPSS
Процентиль: 73%
0.00763
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Directory traversal vulnerability in the web interface (ISALogin.dll) for TAC Vista 4.0, and possibly other versions before 4.3, allows remote attackers to read arbitrary files via ".." sequences in the Template parameter.
EPSS
Процентиль: 73%
0.00763
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other