Описание
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 2.0.5-1.1 |
| cosmic | not-affected | 2.0.5-1.1 |
| dapper | DNE | |
| devel | not-affected | 2.0.5-1.1 |
| esm-apps-legacy/xenial | not-affected | 2.0.5-1.1 |
| esm-apps/bionic | not-affected | 2.0.5-1.1 |
| esm-apps/xenial | not-affected | 2.0.5-1.1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [2.0.5-1.1]] |
| hardy | ignored | end of life |
Показывать по
10
Ссылки на источники
5 Medium
CVSS2
Связанные уязвимости
nvd
около 17 лет назад
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
debian
около 17 лет назад
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG b ...
github
больше 4 лет назад
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
5 Medium
CVSS2