CVE-2014-4306
Directory traversal vulnerability in logs-x.php in WebTitan before 4.04 allows remote attackers to read arbitrary files via a .. (dot dot) in the logfile parameter in a download action.
- Affected products
- Webtitan
- Webtitan
- ≤ 4.01
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 7.6% (94th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2014-06-18
CVE-2014-4306 at NVD
1 known exploit for CVE-2014-4306
Proof-of-concept code and exploit modules indexed by Sploitus