vendor:
SUSIAccess Server
by:
james fitts
7,5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: SUSIAccess Server
Affected Version From: Advantech SUSIAccess <= version 3.0
Affected Version To: Advantech SUSIAccess <= version 3.0
Patch Exists: YES
Related CWE: CVE-2016-9349
CPE: a:advantech:susiaccess_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
Advantech SUSIAccess Server Directory Traversal Information Disclosure
This module exploits an information disclosure vulnerability found in Advantech SUSIAccess <= version 3.0. The vulnerability is triggered when sending a GET request to the server with a series of dot dot slashes (../) in the file parameter.
Mitigation:
Upgrade to Advantech SUSIAccess version 3.1 or later