CVE-2007-3985: Medium severity Securecomputing Securityreporter vulnerability
Directory traversal vulnerability in file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) 4.6.3 allows remote attackers to download arbitrary files via a .. (dot dot) in the name parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3985?
CVE-2007-3985 is classified as a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2007-3985?
To fix CVE-2007-3985, update to a secure version of Secure Computing SecurityReporter that is not vulnerable to directory traversal attacks.
What type of attack can exploit CVE-2007-3985?
CVE-2007-3985 can be exploited through a directory traversal attack that allows attackers to download arbitrary files from the server.
Which software versions are affected by CVE-2007-3985?
CVE-2007-3985 affects version 4.6.3 of Secure Computing SecurityReporter.
What is the impact of CVE-2007-3985 on system security?
The impact of CVE-2007-3985 on system security includes the potential for attackers to gain access to sensitive files on the server.