vendor:
End-to-end FlexPod Management
by:
Kustodian
8,8
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: End-to-end FlexPod Management
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2011-0011
CPE: N/A
Metasploit:
https://www.rapid7.com/db/vulnerabilities/vmsa-2011-0011-cve-2011-3868-player/, https://www.rapid7.com/db/vulnerabilities/vmsa-2011-0011-cve-2011-3868-workstation/, https://www.rapid7.com/db/vulnerabilities/vmsa-2011-0011-cve-2011-3868-fusion/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-0345/, https://www.rapid7.com/db/vulnerabilities/moodle-cve-2011-4286/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
Cloupia End-to-end FlexPod Management – Directory Traversal Vulnerability
Cloupia End-to-end FlexPod Management is vulnerable to a directory traversal attack due to a flaw in the jQuery File Tree Java-Server-Page file. This vulnerability allows an unauthenticated attacker to traverse the file system of the host server, beyond the realm of the web service itself.
Mitigation:
Cloupia are aware of this flaw and are releasing a patch to mitigate access. End users are urged to update immediately by contacting the vendor.