CVE-2014-5370 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows remote attackers to read or possibly delete arbitrary files via a .. (dot dot) in the QUERY_STRING to cfchart.cfchart.
Reference
http://packetstormsecurity.com/files/131504/BlueDragon-CFChart-Servlet-7.1.1.17759-Directory-Traversal.html http://seclists.org/fulldisclosure/2015/Apr/49 http://www.osvdb.org/119527 https://www.exploit-db.com/exploits/36815/ https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-5370/
Share on: