vendor:
Octogate
by:
Oliver Karow
7,5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Octogate
Affected Version From: 3.0.12
Affected Version To: 3.0.12
Patch Exists: YES
Related CWE: N/A
CPE: a:octogate:octogate
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Virtual Appliance & Appliance
2015
Octogate UTM Admin Interface Directory Traversal
Octogate UTM Device is managed via web interface. The download function for SSL-Certifcate and Documentation is accessable without authentication, and allows access to files outside of the web root via the script /scripts/download.php.
Mitigation:
Patch is available from vendor.