RULE(RULE ID:322321)

Rule General Information
Release Date: 2019-07-05
Rule Name: Cybozu s360.exe id Parameter Directory Traversal Vulnerability (CVE-2006-4490)
Severity:
CVE ID:
Rule Protection Details
Description: Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 allow remote authenticated users to read arbitrary files via a .. (dot dot) sequence via the id parameter in (1) scripts/cbag/ag.exe or (2) scripts/s360v2/s360.exe.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: http://cybozu.co.jp/products/dl/notice_060825/
http://jvn.jp/jp/JVN%2390420168/index.html
SecurityTrackerID:1016759
http://vuln.sg/cybozu-en.html
Solutions
Please contact the software vendor to update the software patch.