|
|||
Rule General Information |
---|
Release Date: | 2019-07-05 | |
Rule Name: | Cybozu s360.exe id Parameter Directory Traversal Vulnerability (CVE-2006-4490) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 allow remote authenticated users to read arbitrary files via a .. (dot dot) sequence via the id parameter in (1) scripts/cbag/ag.exe or (2) scripts/s360v2/s360.exe. | |
Impact: | An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information. | |
Affected OS: | Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others | |
Reference: | http://cybozu.co.jp/products/dl/notice_060825/ http://jvn.jp/jp/JVN%2390420168/index.html SecurityTrackerID:1016759 http://vuln.sg/cybozu-en.html |
|
Solutions |
---|
Please contact the software vendor to update the software patch. |