vendor:
CommuniGate Pro
by:
SecurityFocus
7.5
CVSS
HIGH
Arbitrary File Access
22
CWE
Product Name: CommuniGate Pro
Affected Version From: 3.2.2004
Affected Version To: 3.2.2004
Patch Exists: YES
Related CWE: N/A
CPE: a:stalker:communigate_pro
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2000
CommuniGate Pro Arbitrary File Access Vulnerability
It is possible to exploit this vulnerability to read arbitrary files on the filesystem. As CommuniGate Pro runs as root, any file can be accessed. Using this flaw, it is possible to gain enough privilege to remotely execute commands as root.
Mitigation:
Restrict access to the vulnerable system and ensure that all software is up to date.