Overview
Xangati's software release contains relative path traversal (CWE-23) and command injection (CWE-78) vulnerabilities.
Description
Xangati's software release contains relative path traversal (CWE-23) and command injection (CWE-78) vulnerabilities. CWE-23: Relative Path Traversal - CVE-2014-0358 |
Impact
A remote unauthenticated attacker may be able to read system files. A remote authenticated attacker may be able to run arbitrary system commands. |
Solution
Apply an Update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9.4 | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Temporal | 8.2 | E:ND/RL:OF/RC:C |
Environmental | 2.1 | CDP:ND/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Jan Kadijk for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2014-0358, CVE-2014-0359 |
Date Public: | 2014-04-14 |
Date First Published: | 2014-04-14 |
Date Last Updated: | 2014-04-14 20:30 UTC |
Document Revision: | 12 |