Security Advisory

CVE-2019-19372

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-11-28 14:57:58
Last updated 2024-11-15 14:50:48
Assigner mitre
State PUBLISHED

Description

A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potentially download files. NOTE: the discoverer later reported that there was not a "fully working exploit.