Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-6177

Опубликовано: 21 нояб. 2013
Источник: nvd
CVSS2: 3.5
EPSS Низкий

Описание

Directory traversal vulnerability in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allows remote authenticated users to read arbitrary files by leveraging xDashboard access.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:emc:document_sciences_xpression:4.1:sp1:-:*:enterprise:-:-:compuset_engine
cpe:2.3:a:emc:document_sciences_xpression:4.2:-:-:*:enterprise:-:-:compuset_engine
cpe:2.3:a:emc:document_sciences_xpression:4.5:-:-:*:enterprise:-:-:compuset_engine
Конфигурация 2

Одно из

cpe:2.3:a:emc:document_sciences_xpression:4.1:sp1:-:*:enterprise:-:-:publish_engine
cpe:2.3:a:emc:document_sciences_xpression:4.2:-:-:*:enterprise:-:-:publish_engine
cpe:2.3:a:emc:document_sciences_xpression:4.5:-:-:*:enterprise:-:-:publish_engine
Конфигурация 3

Одно из

cpe:2.3:a:emc:document_sciences_xpression:4.1:sp1:-:*:documentum:*:*:*
cpe:2.3:a:emc:document_sciences_xpression:4.2:-:-:*:documentum:*:*:*
cpe:2.3:a:emc:document_sciences_xpression:4.5:-:-:*:documentum:*:*:*

EPSS

Процентиль: 56%
0.00343
Низкий

3.5 Low

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
больше 3 лет назад

Directory traversal vulnerability in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allows remote authenticated users to read arbitrary files by leveraging xDashboard access.

EPSS

Процентиль: 56%
0.00343
Низкий

3.5 Low

CVSS2

Дефекты

CWE-22