CVE-2016-5312
6.5MEDIUM
Summary
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to brightmail/servlet/com.ve.kavachart.servlet.ChartStream.
Refferences
http://www.securityfocus.com/bid/93148
vdb-entryx_refsource_BID
http://www.symantec.com/security_response/securityupdates...
x_refsource_CONFIRM
http://packetstormsecurity.com/files/138891/Symantec-Mess...
x_refsource_MISC
http://www.securitytracker.com/id/1036908
vdb-entryx_refsource_SECTRACK
https://www.exploit-db.com/exploits/40437/
exploitx_refsource_EXPLOIT-DB
http://seclists.org/fulldisclosure/2016/Sep/71
mailing-listx_refsource_FULLDISC
EPSS Score
90% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database