CVE

Id
81174  
CVE No.
CVE-2015-3897  
Status
Candidate  
Description
Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the theme parameter and a file path in the location parameter to bonita/portal/themeResource.  
Phase
Assigned (20150512)  
Votes
None (candidate not yet proposed)  
Comments