CVE-2018-0703: Path Traversal
Published Jan 9, 2019
·Updated
Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via HTTP requests.
Affected Software
1 affected component
Cybozu Office>=10.0.0<=10.8.1
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-0703?
CVE-2018-0703 is a directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 that allows remote attackers to delete arbitrary files via HTTP requests.
2
How can remote attackers exploit CVE-2018-0703?
Remote attackers can exploit CVE-2018-0703 by sending malicious HTTP requests that contain directory traversal sequences to delete arbitrary files.
3
What is the severity of CVE-2018-0703?
CVE-2018-0703 has a severity rating of high with a CVSS score of 7.5.
4
Which version of Cybozu Office is affected by CVE-2018-0703?
Cybozu Office 10.0.0 to 10.8.1 are affected by CVE-2018-0703.
5
How can I fix the directory traversal vulnerability in Cybozu Office?
To fix the directory traversal vulnerability in Cybozu Office, apply the official patch provided by Cybozu.