Home
HIGH: 8.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:NDefault status
unaffected
4.3.0 (cpe) before 4.9.1
affected
Description
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any file on the file system if the target directory contains an XML definition file.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
4.3.0 (cpe) before 4.9.1
References
www.wowza.com/.../wowza-streaming-engine-4-9-1-release-notes
www.rapid7.com/...abilities-in-wowza-streaming-engine-fixed/