{ "CVE_data_meta" : { "ASSIGNER" : "cve@mitre.org", "ID" : "CVE-2011-4948", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "n/a", "version" : { "version_data" : [ { "version_value" : "n/a" } ] } } ] }, "vendor_name" : "n/a" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "Directory traversal vulnerability in admin/remote.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in the type parameter." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "n/a" } ] } ] }, "references" : { "reference_data" : [ { "name" : "[egroupware-german] 20110805 new EGroupware SECURITY & maintenance release 1.8.001.20110805", "refsource" : "MLIST", "url" : "http://comments.gmane.org/gmane.comp.web.egroupware.german/33144" }, { "name" : "[oss-security] 20120328 Re: CVE request: egroupware before 1.8.002 various security issues", "refsource" : "MLIST", "url" : "http://www.openwall.com/lists/oss-security/2012/03/29/1" }, { "name" : "[oss-security] 20120329 Re: CVE request: egroupware before 1.8.002 various security issues", "refsource" : "MLIST", "url" : "http://www.openwall.com/lists/oss-security/2012/03/30/3" }, { "name" : "http://packetstormsecurity.org/files/101676/eGroupware-1.8.001.20110421-Local-File-Inclusion.html", "refsource" : "MISC", "url" : "http://packetstormsecurity.org/files/101676/eGroupware-1.8.001.20110421-Local-File-Inclusion.html" }, { "name" : "http://www.autosectools.com/Advisory/eGroupware-1.8.001.20110421-Local-File-Inclusion-224", "refsource" : "MISC", "url" : "http://www.autosectools.com/Advisory/eGroupware-1.8.001.20110421-Local-File-Inclusion-224" }, { "name" : "http://www.egroupware.org/changelog", "refsource" : "CONFIRM", "url" : "http://www.egroupware.org/changelog" }, { "name" : "http://www.egroupware.org/epl-changelog", "refsource" : "CONFIRM", "url" : "http://www.egroupware.org/epl-changelog" }, { "name" : "52770", "refsource" : "BID", "url" : "http://www.securityfocus.com/bid/52770" } ] } }