vendor:
ChartDirector for .NET
by:
DokFLeed
9
CVSS
CRITICAL
File Access
20
CWE
Product Name: ChartDirector for .NET
Affected Version From: 5.0.1
Affected Version To: Random
Patch Exists: YES
Related CWE: N/A
CPE: a:advsofteng:chartdirector_for_.net
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
ChartDirector Critical File Access
The query variable "cacheId=" is not sanitized, it will can allow critical files download.
Mitigation:
Upgrade to latest Chart Dir or apply the following patch (ChartDirector for .NET Ver 5.0.1 Patch 2): http://www.advsofteng.com/netchartdir501p2.zip