4
CVSSv2

CVE-2009-4511

Published: 13/04/2010 Updated: 10/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to (1) helppage.php or (2) user/helppage.php.

Vulnerable Product Search on Vulmon Subscribe to Product

vsecurity tandberg video communication server x4.1.0

vsecurity tandberg video communication server x4.2.0

vsecurity tandberg video communication server x1.1.0

vsecurity tandberg video communication server x1.2.0

vsecurity tandberg video communication server x4.2.1

vsecurity tandberg video communication server x1.0.0

vsecurity tandberg video communication server x3.0.0

vsecurity tandberg video communication server x3.1.0

vsecurity tandberg video communication server x2.0.0

vsecurity tandberg video communication server x2.1.0

vsecurity tandberg video communication server

Exploits

source: wwwsecurityfocuscom/bid/39389/info TANDBERG Video Communication Server is prone to multiple remote vulnerabilities, including: 1 A file-disclosure vulnerability 2 A security vulnerability that may allow attackers to conduct server impersonation and man-in-middle attacks 3 An authentication-bypass vulnerability An attacker ...
Virtual Security Research, LLC Security Advisory - On December 3rd, VSR identified a directory traversal and file retrieval vulnerability in the TANDBERG's Video Communication Server This issue would allow an authenticated attacker (who has access as an administrator or less privileged user on the web administration interface) to retrieve files f ...