CVE-2016-5312: Path Traversal
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to brightmail/servlet/com.ve.kavachart.servlet.ChartStream.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5312?
CVE-2016-5312 is rated as a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2016-5312?
To fix CVE-2016-5312, upgrade Symantec Messaging Gateway to version 10.6.2 or later.
Who is affected by CVE-2016-5312?
CVE-2016-5312 affects remote authenticated users of Symantec Messaging Gateway versions prior to 10.6.2.
What type of vulnerability is CVE-2016-5312?
CVE-2016-5312 is a directory traversal vulnerability that allows unauthorized file reading.
How can attackers exploit CVE-2016-5312?
Attackers can exploit CVE-2016-5312 by manipulating the 'sn' parameter with a '..' sequence to access arbitrary files.