CVE-2018-13322: Path Traversal
Published Nov 26, 2018
·Updated
Directory traversal in listfolders method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to list directory contents via the "path" parameter.
Affected Software
2 affected components
Buffalo Ts5600d1206 Firmware=3.61-0.10
Buffalo TS5600D1206
Event History
Nov 26, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-13322?
CVE-2018-13322 is a vulnerability that allows attackers to list directory contents on Buffalo TS5600D1206 version 3.61-0.10 through a directory traversal in the list_folders method.
2
How severe is CVE-2018-13322?
CVE-2018-13322 has a severity level of 6.5 (medium).
3
What software versions are affected by CVE-2018-13322?
Buffalo TS5600D1206 version 3.61-0.10 is affected by CVE-2018-13322.
4
How can an attacker exploit CVE-2018-13322?
An attacker can exploit CVE-2018-13322 by using a directory traversal technique to manipulate the 'path' parameter and list the contents of directories.
5
Is Buffalo TS5600D1206 version 3.61-0.10 still vulnerable to CVE-2018-13322?
Yes, Buffalo TS5600D1206 version 3.61-0.10 is still vulnerable to CVE-2018-13322.