CVE-2017-9538

CVE-2017-9538

The ‘Upload logo from external path’ function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent display of a "Cannot exit above the top directory" error message throughout the entire web application) via a ".." in the path field. In other words, the denial of service is caused by an incorrect implementation of a directory-traversal protection mechanism.

Source: CVE-2017-9538

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다