An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File System Collector. The content of the file specified can be viewed in the incoming logs.
The product allows user input to control or influence paths or file names that are used in filesystem operations.
Link | Tags |
---|---|
https://logpoint.com | product |
https://servicedesk.logpoint.com/hc/en-us/articles/18533986803741-Local-File-Inclusion-in-File-System-Collector | vendor advisory |