CVE-2015-0933 - CERT CVE
ID CVE-2015-0933
Sažetak Absolute path traversal vulnerability in ShareLaTeX 0.1.3 and earlier, when the paranoid openin_any setting is omitted, allows remote authenticated users to read arbitrary files via a \include command.
Reference
CVSS
Base: 3.5
Impact: 2.9
Exploitability:6.8
Pristup
VektorSloženostAutentikacija
NETWORK MEDIUM SINGLE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL NONE NONE
CVSS vektor AV:N/AC:M/Au:S/C:P/I:N/A:N
Zadnje važnije ažuriranje 04-03-2015 - 19:09
Objavljeno 04-03-2015 - 02:59