CVE-2016-4314

Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wso2:carbon:4.4.5:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-02-17 02:59

Updated : 2024-02-04 19:11


NVD link : CVE-2016-4314

Mitre link : CVE-2016-4314

CVE.ORG link : CVE-2016-4314


JSON object : View

Products Affected

wso2

  • carbon
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')