Description
There is a path traversal vulnerability in Huawei FusionCube 6.0.2.The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname. Successful exploit could allow the attacker to access a location that is outside of the restricted directory by a crafted filename.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-23706 | There is a path traversal vulnerability in Huawei FusionCube 6.0.2.The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname. Successful exploit could allow the attacker to access a location that is outside of the restricted directory by a crafted filename. |
References
History
No history.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-08-04T01:16:02.790Z
Reserved: 2021-07-20T00:00:00.000Z
Link: CVE-2021-37130
No data.
Status : Modified
Published: 2021-10-27T01:15:07.810
Modified: 2024-11-21T06:14:42.253
Link: CVE-2021-37130
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD