QID 376421
Date Published: 2022-02-24
QID 376421: SearchBlox FileServlet Inclusion Vulnerability.
SearchBlox simplifies enterprise search for complex organizations.
A local file inclusion vulnerability in the FileServlet in SearchBlox
Affected Versions:
SearchBlox before 9.2.2
Successful exploitation of this vulnerability allows unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request.
Solution
Upgrade to the latest version of SearchBlox (9.2.2 or later) searchblox.
Vendor References
- searchblox -
www.tenable.com/cve/CVE-2020-35580 - searchblox-35580 -
hateshape.github.io/general/2021/05/11/CVE-2020-35580.html
CVEs related to QID 376421
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| searchblox |
|