Metrics
Affected Vendors & Products
Tue, 19 Nov 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:landray:landray_ekp:*:*:*:*:*:*:*:* |
Fri, 15 Nov 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Landray
Landray landray Ekp |
|
CPEs | cpe:2.3:a:landray:landray_ekp:16.0:*:*:*:*:*:*:* | |
Vendors & Products |
Landray
Landray landray Ekp |
|
Metrics |
ssvc
|
Fri, 15 Nov 2024 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPreviewFile of the file /sys/ui/sys_ui_component/sysUiComponent.do?method=delPreviewFile. The manipulation of the argument directoryPath leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Landray EKP sysUiComponent.do delPreviewFile path traversal | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-11-15T12:31:04.496Z
Updated: 2024-11-15T20:23:10.217Z
Reserved: 2024-11-15T07:11:20.720Z
Link: CVE-2024-11238
Updated: 2024-11-15T20:22:59.102Z
Status : Analyzed
Published: 2024-11-15T13:15:03.753
Modified: 2024-11-19T19:01:13.060
Link: CVE-2024-11238
No data.