Absolute path traversal vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to read arbitrary files via unspecified vectors.
This category has been deprecated. It was originally used for organizing weaknesses involving file names, which enabled access to files outside of a restricted directory (path traversal) or to perform operations on files that would otherwise be restricted (path equivalence). Consider using either the File Handling Issues category (CWE-1219) or the class Use of Incorrectly-Resolved Name or Reference (CWE-706).
Link | Tags |
---|---|
http://www.christian-schneider.net/advisories/CVE-2014-2232.txt | third party advisory |
http://iw.mapandroute.de/MapAPI-1.1/releaseHistory.jsp | vendor advisory |
http://iw.mapandroute.de/MapAPI-1.0/releaseHistory.jsp | vendor advisory |