Описание
Directory traversal vulnerability in the web interface (ISALogin.dll) for TAC Vista 4.0, and possibly other versions before 4.3, allows remote attackers to read arbitrary files via ".." sequences in the Template parameter.
Ссылки
- Vendor Advisory
- ExploitVendor Advisory
- ExploitVendor Advisory
- Exploit
- Vendor Advisory
- ExploitVendor Advisory
- ExploitVendor Advisory
- Exploit
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:tac:vista:3.0:*:*:*:*:*:*:*
cpe:2.3:a:tac:vista:4.0:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01932
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 4 лет назад
Directory traversal vulnerability in the web interface (ISALogin.dll) for TAC Vista 4.0, and possibly other versions before 4.3, allows remote attackers to read arbitrary files via ".." sequences in the Template parameter.
EPSS
Процентиль: 78%
0.01932
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other