CVE-2011-2474: Path Traversal
Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2474?
CVE-2011-2474 is considered a critical vulnerability as it allows remote attackers to read arbitrary files on the server.
How can CVE-2011-2474 be exploited?
CVE-2011-2474 can be exploited by sending a specially crafted request containing a directory traversal sequence to the affected HTTP server.
What is the impact of CVE-2011-2474 on affected systems?
The impact of CVE-2011-2474 includes unauthorized access to sensitive files, which could lead to data leakage and potential system compromise.
How do I fix CVE-2011-2474?
To fix CVE-2011-2474, it is recommended to upgrade to a non-vulnerable version of Sybase EAServer or implement security measures to block directory traversal attacks.
Which version of Sybase is affected by CVE-2011-2474?
CVE-2011-2474 specifically affects Sybase EAServer version 6.3.1 Developer Edition.