PT-2007-2325 · Ip3 · Ip3 Netaccess
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
IP3 NetAccess versions prior to 4.1.9.6
Description:
The issue allows remote attackers to read arbitrary files via a .. (dot dot) in the
filename parameter in the portalgroups/portalgroups/getfile.cgi endpoint.Recommendations:
For versions prior to 4.1.9.6, update to firmware version 4.1.9.6 to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ip3 Netaccess