2012-08-19 22:55:01 2012-08-20 18:16:14

Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allow remote attackers to read arbitrary files via port-46824 TCP packets specifying a file-open operation with opcode 0x78 and a .. (dot dot) in a pathname, followed by a file-read operation with opcode (1) 0x96, (2) 0x97, or (3) 0x98.

Vector

NETWORK

Complexity

MEDIUM

Authentication

NONE

Confidentiality

PARTIAL

Integrity

NONE

Availability

NONE
Martin Pitt jockey 0.9.7-0ubuntu7.4 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.5 Martin Pitt jockey 0.9.7-0ubuntu7.7 Martin Pitt jockey 0.9.7-0ubuntu7.8 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.1 Martin Pitt jockey 0.9.7-0ubuntu7.9 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.0 Beta 2 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.0 Release Candidate 1 MartiniCreations PassmanLite Password Manager 1.42 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.0 Beta 1 Martin Pitt jockey 0.9.7-0ubuntu7.5 Martin Nagy bind-dyndb-ldap 0.1.0a1 MartiniCreations PassmanLite Password Manager 1.43 Martin Nagy bind-dyndb-ldap 0.1.0b marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-3.0 Beta 1 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-3.1 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.6 Sielcosistemi Winlog lite 2.07.16 (not an official CPE) Martin Pitt jockey 0.9.7-0ubuntu7.2 Martin Lee Multi-lingual E-Commerce System 0.2 MartiniCreations PassmanLite Password Manager 1.44 Martin Pitt jockey 0.9.7-0ubuntu7.6 Sielcosistemi Winlog pro 2.07.16 (not an official CPE) Martin Nagy bind-dyndb-ldap 0.2.0 Martin Nagy bind-dyndb-ldap 1.0.0b1 Martin Pitt jockey 0.9.7-0ubuntu7.11 MartiniCreations PassmanLite Password Manager 1.49 MartiniCreations PassmanLite Password Manager 1.48 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-3.0 Alpha 1 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.2 Martin Nagy bind-dyndb-ldap 1.1.0b1 MartiniCreations PassmanLite Password Manager 1.47 Martin Nagy bind-dyndb-ldap 1.1.0a2 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-3.0 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.3 Martin Nagy bind-dyndb-ldap 1.1.0a1 Martin Nagy bind-dyndb-ldap 1.0.0 release candidate 1 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.x-dev marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.8 MartiniCreations PassmanLite Password Manager 1.46 Martin Nagy bind-dyndb-ldap 1.1.0b2 MartiniCreations PassmanLite Password Manager 1.45 Martin Pitt jockey 0.9.7-0ubuntu7.3 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.4 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.7 marvil07 Vote Up/Down module (vote_up_down) for Drupal 6.x-2.0 Martin Pitt jockey 0.9.7-0ubuntu7.1 Martin Pitt jockey 0.9.7-0ubuntu7 Martin Nagy bind-dyndb-ldap 1.1.0 release candidate 1 MartiniCreations PassmanLite Password Manager 1.50 Marvell Mrvlusgtracking 1.0.0 Marvell Mrvlusgtracking 1.0.7 Martin Pitt jockey 0.9.7-0ubuntu7.10 Marvell Mrvlusgtracking 1.0.1