5.5
CVSSv2

CVE-2013-6720

Published: 06/03/2014 Updated: 29/08/2017
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 555
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x up to and including 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions via a .. (dot dot) in the log parameter, as demonstrated using a crafted request for a customer-support file, as demonstrated by a log file.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm tealeaf cx 8.0

ibm tealeaf cx 8.1

ibm tealeaf cx 7.1

ibm tealeaf cx 7.2

ibm tealeaf cx 8.6

ibm tealeaf cx 8.7

ibm tealeaf cx 8.8

ibm tealeaf cx 8.2

ibm tealeaf cx 8.3

ibm tealeaf cx 8.4

ibm tealeaf cx 8.5

Exploits

# IBM Tealeaf CX (v8 release 8) Remote OS Command Injection # Date: 11/08/2013 # Exploit author: drone # More information: www-01ibmcom/support/docviewwss?uid=swg21667630 # Vendor homepage: www-01ibmcom/software/info/tealeaf/ # Version: Version 8 Release 8 (likely all versions prior) # Tested on: Redhat Linux 62 # CVE: CVE-2013 ...