First published: Wed Dec 19 2012(Updated: )
Multiple directory traversal vulnerabilities on the Huawei E585 device allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the PATH_INFO of an sdcard/ request or (2) modify arbitrary files via a .. (dot dot) in the req_page parameter to en/sms.cgi.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei E585 | ||
Huawei E585u-82 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.