CVE

Id
91133  
CVE No.
CVE-2016-4314  
Status
Candidate  
Description
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.  
Phase
Assigned (20160427)  
Votes
None (candidate not yet proposed)  
Comments