CVE-2015-4666: Path Traversal
Directory traversal vulnerability in opm/readsessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4666?
CVE-2015-4666 is considered a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2015-4666?
To fix CVE-2015-4666, upgrade to a patched version of Xceedium Xsuite that is not vulnerable to this directory traversal attack.
Which versions of Xceedium Xsuite are affected by CVE-2015-4666?
CVE-2015-4666 affects Xceedium Xsuite versions 2.4.4.5 and earlier, including 2.3.0 and 2.4.3.0.
What type of attack does CVE-2015-4666 enable?
CVE-2015-4666 enables remote attackers to perform a directory traversal attack, allowing them to read arbitrary files on the server.
Can CVE-2015-4666 be exploited without authentication?
Yes, CVE-2015-4666 can be exploited without authentication, making it particularly concerning for web applications.