Security Advisory

CVE-2016-5312

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-04-14 18:00:00
Last updated 2024-08-06 01:00:58
Assigner symantec
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to brightmail/servlet/com.ve.kavachart.servlet.ChartStream.