CVE-2017-16609CWE-39

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager

published January 23, 2018

CVSS
EPSS
3%
Percentile
85.8
In the wild
Unconfirmed
What it is

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within download.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download a file. An attacker can leverage this vulnerability to expose sensitive information. Was ZDI-CAN-4750.

The record
Technical detail
CVSS
Not scored
CVSS v4.0
Not supplied
EPSS
0.02851 · 85.8th percentile
Weakness
CWE-39 · Path Traversal: 'C:dirname'
Published
2018-01-23T01:00Z
EPSS history
Timeline
  • 23 JAN 01:00Z
    This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager
    cvelistv5