CVE-2014-9375 Information

Description

Directory traversal vulnerability in the LibraryFileUploadServlet servlet in Lexmark Markvision Enterprise allows remote authenticated users to write to and execute arbitrary files via a .. (dot dot) in a file path in a ZIP archive.

Reference

http://support.lexmark.com/index?page=content&id=TE677 http://www.zerodayinitiative.com/advisories/ZDI-15-046/

Share on: