Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-6483.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-02-13 13:00
Updated : 2018-10-15 15:02
NVD link : CVE-2008-0760
Mitre link : CVE-2008-0760
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
safenet
- sentinel_keys_server
- sentinel_protection_server