First published: Thu May 02 2019(Updated: )
A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in reading of arbitrary files (i.e., significant information disclosure) or file deletion via the nph-viewgif.cgi query string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nih Ncbi Toolbox | >=2.0.7<=2.2.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.