An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an authenticated user to change the filename value (in the POST method) from the original filename to achieve directory traversal via a ../ sequence and, for example, obtain a complete directory listing of the machine.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/157484/Gigamon-GigaVUE-5.5.01.11-Directory-Traversal-File-Upload.html | Third Party Advisory VDB Entry |
https://seclists.org/fulldisclosure/2020/Apr/56 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2020-04-29 14:15
Updated : 2024-02-04 21:00
NVD link : CVE-2020-12251
Mitre link : CVE-2020-12251
CVE.ORG link : CVE-2020-12251
JSON object : View
Products Affected
gigamon
- gigavue
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')