Metrics
Affected Vendors & Products
Tue, 19 Nov 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:landray:landray_ekp:*:*:*:*:*:*:*:* |
Fri, 15 Nov 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Landray
Landray landray Ekp |
|
CPEs | cpe:2.3:a:landray:landray_ekp:16.0:*:*:*:*:*:*:* | |
Vendors & Products |
Landray
Landray landray Ekp |
|
Metrics |
ssvc
|
Fri, 15 Nov 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been found in Landray EKP up to 16.0 and classified as critical. This vulnerability affects the function deleteFile of the file /sys/common/import.do?method=deleteFile of the component API Interface. The manipulation of the argument folder leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Landray EKP API Interface import.do deleteFile path traversal | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-11-15T13:31:04.349Z
Updated: 2024-11-15T20:21:15.845Z
Reserved: 2024-11-15T07:11:23.920Z
Link: CVE-2024-11239
Updated: 2024-11-15T20:21:02.765Z
Status : Analyzed
Published: 2024-11-15T14:15:19.693
Modified: 2024-11-19T19:00:43.230
Link: CVE-2024-11239
No data.