CVE-2013-6720
Beschrijving NL
Directory traversal kwetsbaarheid in download.php in de Passive Capture Application (PCA) webconsole in IBM Tealeaf CX 7.x, 8.x tot en met 8.6, 8.7 voor FP2 en 8.8 voor FP2 stelt op afstand geverifieerde gebruikers in staat om beoogde toegangsbeperkingen te omzeilen via een .. (puntje) in de logparameter, zoals aangetoond met behulp van een vervaardigd verzoek om een klantenondersteuningsbestand, zoals aangetoond door een logbestand.
Origineel (Engels) tonen
Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions via a .. (dot dot) in the log parameter, as demonstrated using a crafted request for a customer-support file, as demonstrated by a log file.