CVE-2010-0154 Information

Description

Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the l parameter related to an \Insecure Direct Object Reference vulnerability.\

Reference

http://www.securityfocus.com/archive/1/513637/100/0/threaded http://www.ventuneac.net/security-advisories/MVSA-10-008

Share on: