First published: Wed Jul 25 2007(Updated: )
Directory traversal vulnerability in file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) 4.6.3 allows remote attackers to download arbitrary files via a .. (dot dot) in the name parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Securecomputing Securityreporter | =4.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3985 is classified as a medium severity vulnerability due to its potential for unauthorized file access.
To fix CVE-2007-3985, update to a secure version of Secure Computing SecurityReporter that is not vulnerable to directory traversal attacks.
CVE-2007-3985 can be exploited through a directory traversal attack that allows attackers to download arbitrary files from the server.
CVE-2007-3985 affects version 4.6.3 of Secure Computing SecurityReporter.
The impact of CVE-2007-3985 on system security includes the potential for attackers to gain access to sensitive files on the server.