vendor:
BlueDragon CFChart Servlet
by:
Mike Westmacott
7.5
CVSS
HIGH
Arbitrary File Retrieval, Directory Traversal
22
CWE
Product Name: BlueDragon CFChart Servlet
Affected Version From: 7.1.1.17759
Affected Version To: 7.1.1.18527
Patch Exists: YES
Related CWE: CVE-2014-5370
CPE: a:new_atlanta:bluedragon_cfchart_servlet:7.1.1.17759
Platforms Tested:
2014
Arbitrary File Retrieval + Deletion In New Atlanta BlueDragon CFChart Servlet
The CFChart servlet of BlueDragon (component com.naryx.tagfusion.cfm.cfchartServlet) is vulnerable to arbitrary file retrieval due to a directory traversal vulnerability. In certain circumstances, the retrieved file is also deleted. An attacker can retrieve files from the server by using a specific URL and intercepting the server's response.
Mitigation:
Update to version 7.1.1.18527 or later to fix the vulnerability. Restrict access to the vulnerable servlet or remove it if not needed.