Directory Traversal Vulnerability in Novell Sentinel Log Manager
CVE-2011-5028
Currently unrated
What is CVE-2011-5028?
The vulnerability in Novell Sentinel Log Manager arises from a directory traversal issue in the FileDownload component. This flaw allows remote authenticated users to access arbitrary files on the server by manipulating the filename parameter with a '..' (dot dot) sequence. As a result, sensitive files may be exposed, posing a significant risk to data security. Proper input validation and restricting file access permissions are crucial to preventing the exploitation of this vulnerability.