First published: Wed Jan 23 2008(Updated: )
Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BitDefender Update Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0396 is considered a high severity vulnerability due to its ability to allow remote attackers to read arbitrary files.
To fix CVE-2008-0396, ensure that your BitDefender Update Server is updated to a version that has patched this directory traversal vulnerability.
CVE-2008-0396 affects BitDefender products, including Security for Fileservers and Enterprise Manager (BDEM).
A directory traversal vulnerability, such as CVE-2008-0396, allows attackers to manipulate file paths to access unauthorized files on a server.
Yes, CVE-2008-0396 can be exploited remotely by sending specially crafted HTTP requests containing dot dot sequences.