LxCenter Kloxo 'Root Directory' Field Directory Traversal Vulnerability
BID:65783
Info
LxCenter Kloxo 'Root Directory' Field Directory Traversal Vulnerability
| Bugtraq ID: | 65783 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2014 12:00AM |
| Updated: | Feb 23 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
LxCenter Kloxo 6.1.17 |
| Not Vulnerable: |
LxCenter Kloxo 6.1.18 |
Discussion
LxCenter Kloxo 'Root Directory' Field Directory Traversal Vulnerability
LxCenter Kloxo is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks.
LxCenter Kloxo prior to 6.1.18 are vulnerable.
LxCenter Kloxo is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks.
LxCenter Kloxo prior to 6.1.18 are vulnerable.
References
LxCenter Kloxo 'Root Directory' Field Directory Traversal Vulnerability
References:
References:
- Kloxo Homepage (LxCenter)
- Kloxo Security #1069 - Any client can gain access to other clients home folder (LxCenter)