CVE-2009-4511

TANDBERG VCS <X5.1 - Path Traversal

Title source: llm
STIX 2.1

Description

Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to (1) helppage.php or (2) user/helppage.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Jon Hart · textwebappsphp
https://www.exploit-db.com/exploits/33832

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_misc
http://www.vsecurity.com/resources/advisory/20100409-3
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/510670/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39275

Scores

EPSS 0.0171
EPSS Percentile 82.4%

Details

CWE
CWE-200
Status published
Products (11)
vsecurity/tandberg_video_communication_server x1.0.0
vsecurity/tandberg_video_communication_server x1.1.0
vsecurity/tandberg_video_communication_server x1.2.0
vsecurity/tandberg_video_communication_server x2.0.0
vsecurity/tandberg_video_communication_server x2.1.0
vsecurity/tandberg_video_communication_server x3.0.0
vsecurity/tandberg_video_communication_server x3.1.0
vsecurity/tandberg_video_communication_server x4.1.0
vsecurity/tandberg_video_communication_server x4.2.0
vsecurity/tandberg_video_communication_server x4.2.1
... and 1 more
Published Apr 13, 2010
Tracked Since Feb 18, 2026