Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to read files on the webserver via a crafted user input.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94823 | vdb entry |
http://www.securitytracker.com/id/1037433 | vdb entry |
https://kc.mcafee.com/corporate/index?page=content&id=SB10181 | vendor advisory |
https://www.exploit-db.com/exploits/40911/ | exploit |