CVE-2012-2202
27.07.2012, 10:27
Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the template parameter.
Vendor | Product | Version |
---|---|---|
ibm | lotus_protector_for_mail_security | 2.1 |
ibm | lotus_protector_for_mail_security | 2.5 |
ibm | lotus_protector_for_mail_security | 2.5.1 |
ibm | lotus_protector_for_mail_security | 2.8 |
ibm | proventia_network_mail_security_system_firmware | 2.5 |
ibm | proventia_network_mail_security_system_firmware | 2.5.0.2 |
ibm | proventia_network_mail_security_system_firmware | 2.5.1 |
ibm | proventia_network_mail_security_system_firmware | 2.6 |
ibm | proventia_network_mail_security_system_firmware | 2.8 |
𝑥
= Vulnerable software versions
References