DataTrack System 3.5 allows remote attackers to list the root directory via a (1) /%u0085/ or (2) /%u00A0/ URI.
References
Configurations
History
21 Nov 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
References | () http://cross-site-scripting.blogspot.com/2010/05/datatrack-system-35-persistent-xss.html - Exploit | |
References | () http://packetstormsecurity.org/1005-exploits/datatrackserver35-xss.txt - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/58734 - |
Information
Published : 2010-05-25 22:30
Updated : 2025-04-11 00:51
NVD link : CVE-2010-2078
Mitre link : CVE-2010-2078
CVE.ORG link : CVE-2010-2078
JSON object : View
Products Affected
magnoware
- datatrack_system
CWE
CWE-20
Improper Input Validation