vendor:
Various HP LaserJet MFP devices
by:
n.runs AG
N/A
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Various HP LaserJet MFP devices
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2010
Directory Traversal in PJL interface
A directory traversal vulnerability has been found in the PJL file system access interface of various HP LaserJet MFP devices. File system access through PJL is usually restricted to a specific part of the file system. Using a pathname such as 0:...... it is possible to get access to the complete file system of the device.