First published: Sat Dec 26 2020(Updated: )
DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal in the fileVirtualPath parameter (the attacker must provide the correct fileOrgName value).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DEXT5 | <=2.7.1262310 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for DEXT5Upload is CVE-2020-35362.
The severity of CVE-2020-35362 is high (7.5).
DEXT5Upload versions up to and including 2.7.1262310 are affected by CVE-2020-35362.
CVE-2020-35362 is a Directory Traversal vulnerability in DEXT5Upload that allows remote files to be downloaded via a specific action with traversal in the fileVirtualPath parameter.
There is no information available regarding a fix for CVE-2020-35362. It is recommended to update to the latest version of DEXT5Upload when a fix becomes available.