First published: Tue Mar 08 2011(Updated: )
Directory traversal vulnerability in the NMS server in Alcatel-Lucent OmniVista 4760 R5.1.06.03 and earlier allows remote attackers to read arbitrary files via directory traversal sequences in HTTP GET requests, related to the lang variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alcatel-Lucent OmniVista | =4760_r5.0.07.05 | |
Alcatel-Lucent OmniVista | <=4760_r5.1.06.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0345 has a medium severity rating due to its ability to allow remote attackers to read arbitrary files.
To fix CVE-2011-0345, upgrade to a version of Alcatel-Lucent OmniVista above 4760 R5.1.06.03.
CVE-2011-0345 affects Alcatel-Lucent OmniVista versions up to and including 4760 R5.1.06.03.
CVE-2011-0345 is a directory traversal vulnerability that allows unauthorized file access.
Yes, CVE-2011-0345 can be exploited remotely through crafted HTTP GET requests.