CVE-2015-0867

Directory traversal vulnerability in SYNCK GRAPHICA Download Log CGI 3.0 and earlier allows remote attackers to read arbitrary files via a crafted filename.
Configurations

Configuration 1 (hide)

cpe:2.3:a:synck_graphica:download_log_cgi:3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:23

Type Values Removed Values Added
References () http://jvn.jp/en/jp/JVN88559134/index.html - Vendor Advisory () http://jvn.jp/en/jp/JVN88559134/index.html - Vendor Advisory
References () http://jvndb.jvn.jp/jvndb/JVNDB-2015-000006 - Vendor Advisory () http://jvndb.jvn.jp/jvndb/JVNDB-2015-000006 - Vendor Advisory
References () http://www.synck.com/blogs/news/weblog_1420694040.html - Vendor Advisory () http://www.synck.com/blogs/news/weblog_1420694040.html - Vendor Advisory

Information

Published : 2015-01-21 15:17

Updated : 2024-11-21 02:23


NVD link : CVE-2015-0867

Mitre link : CVE-2015-0867

CVE.ORG link : CVE-2015-0867


JSON object : View

Products Affected

synck_graphica

  • download_log_cgi
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')