CVE-2017-7442: Path Traversal
Published Aug 3, 2017
·Updated
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.
Affected Software
1 affected component
Gonitro Nitro Pro=11.0.3.173
Event History
Aug 3, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-7442?
The severity of CVE-2017-7442 is considered critical due to the potential for remote code execution.
2
How do I fix CVE-2017-7442?
To fix CVE-2017-7442, update Nitro Pro to the latest version provided by the vendor as it addresses the vulnerability.
3
What software is affected by CVE-2017-7442?
CVE-2017-7442 specifically affects Nitro Pro version 11.0.3.173.
4
What attack vectors are exploited in CVE-2017-7442?
CVE-2017-7442 can be exploited through directory traversal sequences in the saveAs and launchURL calls.
5
Can CVE-2017-7442 be exploited remotely?
Yes, CVE-2017-7442 allows remote attackers to execute arbitrary code, making it exploitable remotely.