CVE-2013-6720

EXPLOITED

IBM Tealeaf CX - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions via a .. (dot dot) in the log parameter, as demonstrated using a crafted request for a customer-support file, as demonstrated by a log file.

Exploits (1)

exploitdb WORKING POC
by drone · pythonwebappsphp
https://www.exploit-db.com/exploits/32546

Scores

EPSS 0.0409
EPSS Percentile 88.6%

Details

VulnCheck KEV 2022-01-12
CWE
CWE-22
Status published
Products (11)
ibm/tealeaf_cx 7.1
ibm/tealeaf_cx 7.2
ibm/tealeaf_cx 8.0
ibm/tealeaf_cx 8.1
ibm/tealeaf_cx 8.2
ibm/tealeaf_cx 8.3
ibm/tealeaf_cx 8.4
ibm/tealeaf_cx 8.5
ibm/tealeaf_cx 8.6
ibm/tealeaf_cx 8.7
... and 1 more
Published Mar 06, 2014
Tracked Since Feb 18, 2026