Auktion.CGI.Directory.Traversal

description-logoDescription

It indicates a directory traversal vulnerability in HIS Software Auktion.


Due to inadequate input sanitization, a remote attacker can read arbitrary files and possibly execute commands on a target system by sending it a specially-crafted message.

affected-products-logoAffected Products

Any unprotected HIS Auktion 1.62 is vulnerable.

Impact logoImpact

Attackers can read arbitrary files or even execute arbitrary commands on the victim system.

recomended-action-logoRecommended Actions

Apply appropriate patches or upgrade the software to the latest non-vulnerable version.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2018-11-20 13.494 Default_action:pass:drop