First published: Tue Mar 18 2014(Updated: )
Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Web Appliance Firmware | <=3.7.8.1 | |
Sophos Web Appliance Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-2641 is classified as high due to its potential to allow remote attackers to read arbitrary files.
To fix CVE-2013-2641, upgrade the Sophos Web Appliance firmware to version 3.7.8.2 or later.
CVE-2013-2641 affects Sophos Web Appliance versions prior to 3.7.8.2.
CVE-2013-2641 is a directory traversal vulnerability that enables unauthorized file access.
Yes, CVE-2013-2641 can be exploited remotely by attackers using the id parameter.