ABB Cylon Aspect 3.08.01 calendarFileDelete.php Arbitrary File Deletion

Discussion in 'News Aggregator' started by Packet Storm, 9 Oct 2024.

  1. Packet Storm

    Packet Storm Guest

    ABB Cylon Aspect version 3.08.01 suffers from an arbitrary file deletion vulnerability. Input passed to the file parameter in calendarFileDelete.php is not properly sanitized before being used to delete calendar files. This can be exploited by an unauthenticated attacker to delete files with the permissions of the web server using directory traversal sequences passed within the affected POST parameter.

    Continue reading...
     

Share This Page

Loading...