CVE-2011-0345: Path Traversal
Published Mar 8, 2011
·Updated
Directory traversal vulnerability in the NMS server in Alcatel-Lucent OmniVista 4760 R5.1.06.03 and earlier allows remote attackers to read arbitrary files via directory traversal sequences in HTTP GET requests, related to the lang variable.
Affected Software
2 affected components
Alcatel-Lucent OmniVista<=4760_r5.1.06.03
Alcatel-Lucent OmniVista=4760_r5.0.07.05
Event History
Mar 8, 2011
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0345?
CVE-2011-0345 has a medium severity rating due to its ability to allow remote attackers to read arbitrary files.
2
How do I fix CVE-2011-0345?
To fix CVE-2011-0345, upgrade to a version of Alcatel-Lucent OmniVista above 4760 R5.1.06.03.
3
What software is affected by CVE-2011-0345?
CVE-2011-0345 affects Alcatel-Lucent OmniVista versions up to and including 4760 R5.1.06.03.
4
What type of vulnerability is CVE-2011-0345?
CVE-2011-0345 is a directory traversal vulnerability that allows unauthorized file access.
5
Can CVE-2011-0345 be exploited remotely?
Yes, CVE-2011-0345 can be exploited remotely through crafted HTTP GET requests.