Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attackers to read arbitrary files via the url_name parameter.
References
Link | Resource |
---|---|
https://blog.rapid7.com/2013/11/06/supermicro-ipmi-firmware-vulnerabilities/ | Not Applicable |
https://www.tenable.com/cve/CVE-2013-6785 | Third Party Advisory |
https://blog.rapid7.com/2013/11/06/supermicro-ipmi-firmware-vulnerabilities/ | Not Applicable |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:59
Type | Values Removed | Values Added |
---|---|---|
References | () https://blog.rapid7.com/2013/11/06/supermicro-ipmi-firmware-vulnerabilities/ - Not Applicable |
Information
Published : 2020-01-23 15:15
Updated : 2024-11-21 01:59
NVD link : CVE-2013-6785
Mitre link : CVE-2013-6785
CVE.ORG link : CVE-2013-6785
JSON object : View
Products Affected
supermicro
- intelligent_platform_management_interface
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')