CVE-2012-4957: Path Traversal
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a /FSF/CMD request with a full pathname in a PATH element of an SRS record.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4957?
CVE-2012-4957 is classified as a high severity vulnerability due to its potential to allow remote attackers to access sensitive files.
How do I fix CVE-2012-4957?
To fix CVE-2012-4957, upgrade to the latest version of Novell File Reporter that addresses this vulnerability.
What is the impact of CVE-2012-4957?
The impact of CVE-2012-4957 allows unauthorized remote access to arbitrary files on the affected system.
Which software is affected by CVE-2012-4957?
CVE-2012-4957 affects Novell File Reporter version 1.0.2.
How does CVE-2012-4957 exploit path traversal?
CVE-2012-4957 exploits path traversal by using a /FSF/CMD request that incorporates a full pathname in the PATH element of an SRS record.