Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise prior to 3.1.5 allows remote malicious users to read or delete arbitrary files via a full pathname.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ge mds pulsenet |