An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an authenticated user to change the filename value (in the POST method) from the original filename to achieve directory traversal via a ../ sequence and, for example, obtain a complete directory listing of the machine.
References
Link | Resource |
---|---|
https://seclists.org/fulldisclosure/2020/Apr/56 | Mailing List Third Party Advisory |
http://packetstormsecurity.com/files/157484/Gigamon-GigaVUE-5.5.01.11-Directory-Traversal-File-Upload.html | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-04-29 07:15
Updated : 2020-05-18 08:47
NVD link : CVE-2020-12251
Mitre link : CVE-2020-12251
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
gigamon
- gigavue