Description
Directory traversal vulnerability in VDG Security SENSE (formerly DIVA) 2.3.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI to images/.
References (5)
Core 5
Core References
Exploit mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Dec/76
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/71736
Exploit x_refsource_misc
http://packetstormsecurity.com/files/129656/VDG-Security-SENSE-2.3.13-File-Disclosure-Bypass-Buffer-Overflow.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99331
Scores
EPSS
0.0283
EPSS Percentile
84.9%
Details
CWE
CWE-22
Status
published
Products (1)
vdgsecurity/vdg_sense
2.3.13
Published
Jan 02, 2015
Tracked Since
Feb 18, 2026