CVE-2015-4666
Xceedium Xsuite - Multiple Vulnerabilities
Record summary
CVE-2015-4666 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBXceedium Xsuite - Multiple VulnerabilitiesExploitDB exploitby modzeroNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMXceedium Xsuite <=2.4.4.5 - Local File InclusionCVSS 5
Xceedium Xsuite 2.4.4.5 and earlier is vulnerable to local file inclusion via opm/read_sessionlog.php that allows remote attackers to read arbitrary files in the logFile parameter.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access, disclosure of sensitive information, and potential remote code execution.
Remediation
Upgrade Xceedium Xsuite to a version higher than 2.4.4.5 or apply the necessary patches provided by the vendor.
Source: ProjectDiscovery