vendor:
Fiery Controller SW2.0
by:
Unknown
7,5
CVSS
HIGH
Arbitrary File Disclosure
22
CWE
Product Name: Fiery Controller SW2.0
Affected Version From: EFI Fiery Controller SW2.0
Affected Version To: Xerox DocuColor 260, 250, 242
Patch Exists: Unknown
Related CWE: Unknown
CPE: a:electronics_for_imaging:fiery_controller_sw2.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
Unknown
Xerox DC260 EFI Fiery Controller Webtools 2.0 Arbitrary File Disclosure
Input passed thru the 'file' GET parameter in 'forceSave.php' script is not properly sanitized before being used to read files. This can be exploited by an unauthenticated attacker to read arbitrary files on the affected system.
Mitigation:
Ensure that user input is properly sanitized before being used to read files.