CVE-2019-6500
EUVD-2019-1605921.01.2019, 06:29
In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' characters, as demonstrated by an initial /h2hdocumentation//%2e%2e/ substring.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| axway | file_tranfer_direct | 2.7.1 |
𝑥
= Vulnerable software versions
References