IBM Lotus Expeditor 'Eclipse Help' Component Directory Traversal Vulnerability
BID:54164
Info
IBM Lotus Expeditor 'Eclipse Help' Component Directory Traversal Vulnerability
| Bugtraq ID: | 54164 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-0186 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2012 12:00AM |
| Updated: | May 31 2013 02:44PM |
| Credit: | IBM |
| Vulnerable: |
IBM WebSphere Commerce 7.0 IBM WebSphere Commerce 6.0 |
| Not Vulnerable: | |
Discussion
IBM Lotus Expeditor 'Eclipse Help' Component Directory Traversal Vulnerability
IBM Lotus Expeditor is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from local resources. This may aid further attacks.
IBM Lotus Expeditor is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from local resources. This may aid further attacks.
Exploit / POC
IBM Lotus Expeditor 'Eclipse Help' Component Directory Traversal Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM Lotus Expeditor 'Eclipse Help' Component Directory Traversal Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
IBM Lotus Expeditor 'Eclipse Help' Component Directory Traversal Vulnerability
References:
References: