Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of the restricted directory on the remote server.
References
| Link | Resource |
|---|---|
| https://mayaseven.com/nimble-directory-traversal-in-nimble-streamer-version-3-0-2-2-to-3-5-4-9/ | Exploit Third Party Advisory |
| http://packetstormsecurity.com/files/154196/Nimble-Streamer-3.x-Directory-Traversal.html | Exploit Third Party Advisory VDB Entry |
Configurations
Information
Published : 2019-08-22 08:15
Updated : 2019-08-27 09:19
NVD link : CVE-2019-11013
Mitre link : CVE-2019-11013
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
softvelum
- nimble_streamer


