CVE-2018-12314: Path Traversal
Published Dec 4, 2018
·Updated
Directory Traversal in downloadwallpaper.cgi in ASUSTOR ADM version 3.1.1 allows attackers to download arbitrary files by manipulating the "file" and "folder" URL parameters.
Affected Software
2 affected components
ASUSTOR Data Master=3.1.1
ASUSTOR As602t
Event History
Dec 4, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-12314.
2
What is the severity of CVE-2018-12314?
The severity of CVE-2018-12314 is high with a value of 7.5.
3
Which version of ASUSTOR ADM is affected by CVE-2018-12314?
ASUSTOR ADM version 3.1.1 is affected by CVE-2018-12314.
4
How can attackers exploit CVE-2018-12314?
Attackers can exploit CVE-2018-12314 by manipulating the "file" and "folder" URL parameters in downloadwallpaper.cgi to download arbitrary files.
5
Are there any known fixes for CVE-2018-12314?
At the moment, there are no known fixes for CVE-2018-12314. It is recommended to stay updated with the latest security patches released by ASUSTOR.