{ "id": "CVE-2011-4518", "sourceIdentifier": "cret@cert.org", "published": "2013-05-23T17:55:02.807", "lastModified": "2013-06-03T04:00:00.000", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors." }, { "lang": "es", "value": "Vulnerabilidad de salto de directorio en el objeto PmWebDir en el servidor web en MICROSYS Promotic antes de v8.1.5 permite a atacantes remotos leer archivos de su elecci\u00f3n a trav\u00e9s de vectores no especificados." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-22" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:*:*:*:*:*:*:*:*", "versionEndIncluding": "8.1.4", "matchCriteriaId": "28A6D558-5C0D-45D9-86F9-51415FDAEBE0" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "02178943-2743-47D5-B9C4-AB949988DC1D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "7357AA05-5785-4457-8419-07D50963B72E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "C2C61222-F8FD-40DA-8BEB-214D84C9776A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.3:*:*:*:*:*:*:*", "matchCriteriaId": "D10CCACE-AFB3-48DC-8B4D-C7A612083C86" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.4:*:*:*:*:*:*:*", "matchCriteriaId": "656C8269-02BC-446D-9DE8-9C05BCD73642" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.5:*:*:*:*:*:*:*", "matchCriteriaId": "7E9BB1C0-980B-476E-9C4C-6CA5C0C935CC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.6:*:*:*:*:*:*:*", "matchCriteriaId": "C9D0E060-A295-4FA8-8E83-3555376B1DD9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.7:*:*:*:*:*:*:*", "matchCriteriaId": "9A893332-E407-475C-A0A3-3D553BEAF7A9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.8:*:*:*:*:*:*:*", "matchCriteriaId": "6C1E4F8D-61B9-463D-9642-800A0CF425EE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.9:*:*:*:*:*:*:*", "matchCriteriaId": "70455EAC-1F80-4B06-9524-2014A9245296" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.10:*:*:*:*:*:*:*", "matchCriteriaId": "6C171B19-3889-4B4E-B7FE-0B7CEA3AED43" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.11:*:*:*:*:*:*:*", "matchCriteriaId": "FEC60655-5D1C-40A6-877B-990618764E56" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.12:*:*:*:*:*:*:*", "matchCriteriaId": "98EF64C6-DD93-40AE-A354-324657BD69C9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.0.13:*:*:*:*:*:*:*", "matchCriteriaId": "9EAEA85A-34B2-4EE4-B431-124DFE690AF1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.1.0:*:*:*:*:*:*:*", "matchCriteriaId": "8B5CB21B-4E56-4145-9E42-EAA464A3E00D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "0BDDFCCF-7E92-47B3-BF14-C1A3AE7253F4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "86EFD69D-C3C6-497F-B651-FEE7C4992DA8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:microsys:promotic:8.1.3:*:*:*:*:*:*:*", "matchCriteriaId": "B33DB525-2F9D-477D-908E-C30B6F4F57B6" } ] } ] } ], "references": [ { "url": "http://ics-cert.us-cert.gov/advisories/ICSA-12-024-02", "source": "cret@cert.org", "tags": [ "US Government Resource" ] }, { "url": "http://www.promotic.eu/en/pmdoc/News.htm#ver80105", "source": "cret@cert.org" } ] }