Security Advisory

CVE-2014-2846

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2014-04-28 14:00:00
Last updated 2024-08-06 10:28:46
Assigner mitre
State PUBLISHED

Description

Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request to login/doLogin.