Dot CMS Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2016-3972 - Vulnerability Database

Dot CMS Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2016-3972

Low
Reference: CVE-2016-3972
Title: Dot CMS Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:

Directory traversal vulnerability in the dotTailLogServlet in dotCMS before 3.5.1 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the fileName parameter.