First published: Tue Jul 25 2017(Updated: )
Directory traversal vulnerability in the web request/response interface in Appserver before 1.0.3 allows remote attackers to read normally inaccessible files via a .. (dot dot) in a crafted URL.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
BTCPayServer | <=1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1847 has been classified as a medium severity vulnerability due to its potential for unauthorized file access.
To fix CVE-2015-1847, update the Appserver software to version 1.0.3 or later to eliminate the directory traversal vulnerability.
CVE-2015-1847 affects versions of Appserver prior to 1.0.3.
A directory traversal vulnerability allows attackers to access restricted directories and read files on the server using manipulation of file paths.
Yes, if exploited, CVE-2015-1847 can allow attackers to read sensitive files on the server, leading to potential data exposure.