Security Advisory

CVE-2014-5236

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-01-31 21:16:52
Last updated 2024-08-06 11:41:48
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.