CVE-2021-29395
Summary
| CVE | CVE-2021-29395 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-04 19:15:00 UTC |
| Updated | 2022-02-08 19:41:00 UTC |
| Description | Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Globalnorthstar | Northstar Club Management | 6.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ardent Security | Security Services to Help Your Business Withstand Cyber Attacks | MISC | Ardent-Security.com | |
| ASA-2021-03 | Ardent Security | MISC | ardent-security.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.