First published: Tue Apr 13 2010(Updated: )
Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to (1) helppage.php or (2) user/helppage.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tandberg Video Communication Server | <=x4.3.0 | |
Tandberg Video Communication Server | =x1.0.0 | |
Tandberg Video Communication Server | =x1.1.0 | |
Tandberg Video Communication Server | =x1.2.0 | |
Tandberg Video Communication Server | =x2.0.0 | |
Tandberg Video Communication Server | =x2.1.0 | |
Tandberg Video Communication Server | =x3.0.0 | |
Tandberg Video Communication Server | =x3.1.0 | |
Tandberg Video Communication Server | =x4.1.0 | |
Tandberg Video Communication Server | =x4.2.0 | |
Tandberg Video Communication Server | =x4.2.1 | |
<=x4.3.0 | ||
=x1.0.0 | ||
=x1.1.0 | ||
=x1.2.0 | ||
=x2.0.0 | ||
=x2.1.0 | ||
=x3.0.0 | ||
=x3.1.0 | ||
=x4.1.0 | ||
=x4.2.0 | ||
=x4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4511 is considered to have a moderate severity level due to its potential for directory traversal vulnerabilities.
To fix CVE-2009-4511, upgrade to version X5.1 or later of the Tandberg Video Communication Server.
CVE-2009-4511 affects multiple versions of the Tandberg Video Communication Server prior to X5.1.
CVE-2009-4511 facilitates a directory traversal attack, allowing attackers to access arbitrary files on the server.
No, CVE-2009-4511 requires remote authenticated users to exploit the vulnerability.