Security Advisory

CVE-2010-0154

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2010-09-14 16:39:00
Last updated 2024-08-07 00:37:54
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the l parameter, related to an "Insecure Direct Object Reference vulnerability."