packetstormsecurity.com
http://packetstormsecurity.com/files/150541/Tarantella-Enterprise-Directory-Traversal.html CVE-2018-19753
HIGHNuclei
Tarantella Enterprise <3.11 - Local File Inclusion
Record summary
CVE-2018-19753 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Tarantella Enterprise before 3.11 allows Directory Traversal.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHTarantella Enterprise <3.11 - Local File InclusionCVSS 7.5
Tarantella Enterprise versions prior to 3.11 are susceptible to local file inclusion.
Impact
Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the target system.
Remediation
Upgrade Tarantella Enterprise to version 3.11 or higher to mitigate this vulnerability.
WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2018packetstormsecliststarantellalfioraclevuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:oracle:tarantella_enterprise:*:*:*:*:*:*:*:*
https://packetstormsecurity.com/files/150541/Tarantella-Enterprise-Directory-Traversal.html https://nvd.nist.gov/vuln/detail/CVE-2018-19753 http://seclists.org/fulldisclosure/2018/Nov/66 http://packetstormsecurity.com/files/150541/Tarantella-Enterprise-Directory-Traversal.html https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
320181130 CVE-2018-19753 - Directory Traversal in Tarantella Enterprise before 3.11mailing list
http://seclists.org/fulldisclosure/2018/Nov/66 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-19753