Security Advisory

CVE-2008-3150

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-07-11 18:00:00
Last updated 2024-08-07 09:28:41
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in index.php in Neutrino Atomic Edition 0.8.4 allows remote attackers to read and modify files, as demonstrated by manipulating data/sess.php in (1) usb and (2) del_pag actions. NOTE: this can be leveraged for code execution by performing an upload that bypasses the intended access restrictions that were implemented in sess.php.