5
CVSSv2

CVE-2015-2166

Published: 06/04/2015 Updated: 03/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote malicious users to read arbitrary files via a ..%2f (dot dot encoded slash) in the default URI.

Vulnerable Product Search on Vulmon Subscribe to Product

ericsson drutt mobile service delivery platform 6.0

ericsson drutt mobile service delivery platform 4.0

ericsson drutt mobile service delivery platform 5.0

Exploits

+------------------------------------------------------------------------------------------------------+ + Ericsson Drutt MSDP (Instance Monitor) - Directory Traversal Vulnerability and Arbitrary File Access + +------------------------------------------------------------------------------------------------------+ Affected Product: Ericsson Drutt MS ...
Ericsson Drutt MSDP (Instance Monitor) versions 4, 5, and 6 suffer from directory traversal and arbitrary file access vulnerabilities ...

Github Repositories

A PoC exploit for CVE-2015-2166 - Directory Traversal Vulnerability in Ericsson Drutt Mobile Service Delivery Platform (MSDP)

CVE-2015-2166 - Directory Traversal Vulnerability in Ericsson Drutt Mobile Service Delivery Platform (MSDP) CVE-2015-2166 is a directory traversal vulnerability that affects the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) versions 4, 5, and 6 The vulnerability allows remote attackers to read arbitrary files on the affected system by exploiting a