Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2009-4511
StatusCandidate
DescriptionMultiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to (1) helppage.php or (2) user/helppage.php.
SeverityMedium
CVSS score4
CVSS vector(AV:N/AC:L/Au:S/C:P/I:N/A:N)
PhaseAssigned (17.04.2010)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4511
ReferencesBUGTRAQ : 20100410 CVE-2009-4511: TANDBERG VCS Arbitrary File Retrieval
 MISC : http://www.vsecurity.com/resources/advisory/201004...
 SECUNIA : 39275
SecurityVulns:TANDBERG Video Communication Server multiple security vulnerabilities

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru