3Com_Network_Supervisor_Directory_Traversal_attack

Strike ID:
G05-4k401
CVSS:
5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
False Positive:
f
Variants:
1
Year:
2005

Description

A directory traversal vulnerability exists in the 3Com Network Supervisor product. The flaw is caused by insufficient sanitization of HTTP requests. This vulnerability allows an unauthorized user to read arbitrary files on the target host. The target will not exhibit any unusual behaviour as a result of this attack. A successful attack will result in potentially sensitive information being disclosed to an unprivileged user. The content of arbitrary files, specified by the attacker in the request will be served in the HTTP response.

CVE

References

Bid