Cantata Internal HTTP Server Path Traversal Arbitrary File Download Vulnerability
BID:65037
Info
Cantata Internal HTTP Server Path Traversal Arbitrary File Download Vulnerability
| Bugtraq ID: | 65037 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-7300 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 23 2013 12:00AM |
| Updated: | Apr 16 2015 05:49PM |
| Credit: | Nickollai |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cantata Internal HTTP Server Path Traversal Arbitrary File Download Vulnerability
Cantata is prone to a vulnerability that lets attackers download arbitrary files because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to download arbitrary files within the context of the web server process. Information harvested may aid in launching further attacks.
Cantata is prone to a vulnerability that lets attackers download arbitrary files because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to download arbitrary files within the context of the web server process. Information harvested may aid in launching further attacks.
Solution / Fix
Cantata Internal HTTP Server Path Traversal Arbitrary File Download Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cantata Internal HTTP Server Path Traversal Arbitrary File Download Vulnerability
References:
References: