CVE-2019-16064 Information
Feb 14, 2021
cve
Description
NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files and directories stored outside of the web root folder. By exploiting this vulnerability it is possible for an attacker to list operating-system directory contents on the server create directories and upload files in permissible locations and modify filenames and delete files that are accessible by the user running the web server instance.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Reference
https://www.mogozobo.com/?p=3647
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
9.6
Share on: