CVE-2021-36717

Synerion TimeNet version 9.21 contains a directory traversal vulnerability where, on the "Name" parameter, the attacker can return to the root directory and open the host file. This might give the attacker the ability to view restricted files, which could provide the attacker with more information required to further compromise the system.
References
Link Resource
https://www.gov.il/en/departments/faq/cve_advisories Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:synerion:timenet:9.21:*:*:*:*:*:*:*

Information

Published : 2021-09-07 05:15

Updated : 2021-12-16 12:34


NVD link : CVE-2021-36717

Mitre link : CVE-2021-36717


JSON object : View

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Advertisement

dedicated server usa

Products Affected

synerion

  • timenet