In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' characters, as demonstrated by an initial /h2hdocumentation//%2e%2e/ substring.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
axway file tranfer direct 2.7.1 |