10
CVSSv2

CVE-2015-6459

Published: 18/09/2015 Updated: 23/09/2015
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise prior to 3.1.5 allows remote malicious users to read or delete arbitrary files via a full pathname.

Vulnerable Product Search on Vulmon Subscribe to Product

ge mds pulsenet