CVE-2008-0396

high

Description

Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/39802

http://www.vupen.com/english/advisories/2008/0213

http://www.securityfocus.com/archive/1/486701/100/0/threaded

http://securityreason.com/securityalert/3568

http://secunia.com/advisories/28578

http://oliver.greyhat.de/2008/01/19/bitdefender-unauthorized-remote-file-access-vulnerability/

Details

Source: Mitre, NVD

Published: 2008-01-23

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High