ABB Cylon Aspect 3.08.01 persistenceManagerAjax.php Directory Traversal

Discussion in 'News Aggregator' started by Packet Storm, 11 Oct 2024.

  1. Packet Storm

    Packet Storm Guest

    ABB Cylon Aspect version 3.08.01 has a directory traversal vulnerability that can be exploited by an unauthenticated attacker to list the contents of arbitrary directories without reading file contents, leading to information disclosure of directory structures and filenames. This may expose sensitive system details, aiding in further attacks. The issue lies in the listFiles() function of the persistenceManagerAjax.php script, which calls PHP's readdir() function without proper input validation of the directory POST parameter.

    Continue reading...
     

Share This Page

Loading...