Directory Traversal Vulnerability in Lexmark Markvision Enterprise
CVE-2014-9375

Currently unrated

Key Information:

Vendor

Lexmark

Vendor
CVE Published:
16 February 2015

What is CVE-2014-9375?

A directory traversal vulnerability exists in the LibraryFileUploadServlet of Lexmark Markvision Enterprise. This flaw allows remote authenticated users to manipulate file paths using '..' (dot dot) sequences, enabling them to write to and execute arbitrary files contained within a ZIP archive. Proper safeguards against such path traversal attacks are crucial to prevent unauthorized access and potential compromise of system integrity.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2014-9375 : Directory Traversal Vulnerability in Lexmark Markvision Enterprise