5
CVSSv2

CVE-2013-2641

Published: 18/03/2014 Updated: 19/03/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in patience.cgi in Sophos Web Appliance prior to 3.7.8.2 allows remote malicious users to read arbitrary files via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sophos web_appliance_firmware

sophos web_appliance -

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20130403-0 > ======================================================================= title: Multiple vulnerabilities product: Sophos Web Protection Appliance vulnerable version: <= 3781 fixed version: 3782 impact: Critical CVE num ...
Sophos Web Protection Appliance version 3781 suffers from OS command injection, cross site scripting, and file disclosure vulnerabilities ...