Directory Traversal Vulnerability in Novell Sentinel Log Manager
CVE-2011-5028
Currently unrated
Summary
The vulnerability in Novell Sentinel Log Manager arises from a directory traversal issue in the FileDownload component. This flaw allows remote authenticated users to access arbitrary files on the server by manipulating the filename parameter with a '..' (dot dot) sequence. As a result, sensitive files may be exposed, posing a significant risk to data security. Proper input validation and restricting file access permissions are crucial to preventing the exploitation of this vulnerability.
References
EPSS Score
14% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved