Security Advisory

CVE-2012-1089

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-03-23 18:00:00
Last updated 2024-08-06 18:45:27
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.