Quantcast
Channel: Info Disclosure Files ≈ Packet Storm
Viewing all articles
Browse latest Browse all 141

ABB Cylon Aspect 3.08.01 persistenceManagerAjax.php Directory Traversal

$
0
0
ABB Cylon Aspect version 3.08.01 has a directory traversal vulnerability that can be exploited by an unauthenticated attacker to list the contents of arbitrary directories without reading file contents, leading to information disclosure of directory structures and filenames. This may expose sensitive system details, aiding in further attacks. The issue lies in the listFiles() function of the persistenceManagerAjax.php script, which calls PHP's readdir() function without proper input validation of the directory POST parameter.

Viewing all articles
Browse latest Browse all 141

Trending Articles