CVE-2018-15706
published 2018-10-31CVE-2018-15706: WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal…
PriorityP353medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
32.37%
98.1th percentile
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| advantech | advantech_webaccess | — | — |
| advantech | webaccess | — | — |
| advantech | webaccess | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:C/I:N/A:N
vendor_apache5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8g8q-89jc-69gc: WADashboard API in Advantech WebAccess 8
ghsa_unreviewed·2022-05-14
CVE-2018-15706 [MEDIUM] CWE-22 GHSA-8g8q-89jc-69gc: WADashboard API in Advantech WebAccess 8
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.
Apache
Apache tomcat: CVE-2017-15706
vendor_apache·CVSS 5.3
CVE-2017-15706 [MEDIUM] Apache tomcat: CVE-2017-15706
Apache tomcat: CVE-2017-15706
As part of the fix for bug 61201 , the description of the search algorithm used by the CGI Servlet to identify which script to execute was updated. The update was not correct. As a result, some scripts may have failed to execute as expected and other scripts may have been executed unexpectedly. Note that the behaviour of the CGI servlet has remained unchanged in this regard. It is only the documentation of the behaviour that was wrong and has been corrected. This was fixed in revision 1814827 . This issue was reported to the Apache Tomcat Security Team by Jan Michael Greiner on 17 September 2017 and made public on 31 January 2018. Affects: 8.0.45 to 8.0.47 30 November 2017 Fixed in Apache Tomcat 8.5.24 Low: Incorrectly documented CGI search algorithm
No detection rules found.
No public exploits indexed.
2018-10-31
Published