MEDIUM
Multiple directory traversal vulnerabilities in pfSense before 2.1.4 allow (1) remote attackers to read arbitrary .info files via a crafted path in the pkg parameter to pkg_mgr_install.php and allow (2) remote authenticated users to read arbitrary files via the downloadbackup parameter to system_firmware_restorefullbackup.php
Published Jul 2, 2014
5.0
MEDIUMCVSS 2.0
EPSS 3.50%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.