5
CVSSv2

CVE-2014-5350

Published: 19/08/2014 Updated: 20/08/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in Bitdefender GravityZone prior to 5.1.11.432 allow remote malicious users to read arbitrary files via a (1) .. (dot dot) in the id parameter to webservice/CORE/downloadFullKitEpc/a/1 in the Web Console or (2) %2E%2E (encoded dot dot) in the default URI to port 7074 on the Update Server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bitdefender gravityzone

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20140716-3 > ======================================================================= title: Multiple critical vulnerabilities product: Bitdefender GravityZone vulnerable version: <5111432 fixed version: >=5111432 impact: critical ...