Description
Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the selection parameter.
Exploits
References
cve@mitre.org
http://packetstormsecurity.com/files/129052/Progress-OpenEdge-11.2-Directory-Traversal.htmlcve@mitre.org
http://www.exploit-db.com/exploits/35127cve@mitre.org
http://www.exploit-db.com/exploits/35207cve@mitre.org
https://www.xlabs.com.br/blog/?p=256af854a3a-2127-422b-91ae-364da2661108
http://packetstormsecurity.com/files/129052/Progress-OpenEdge-11.2-Directory-Traversal.htmlaf854a3a-2127-422b-91ae-364da2661108
http://www.exploit-db.com/exploits/35127af854a3a-2127-422b-91ae-364da2661108
http://www.exploit-db.com/exploits/35207af854a3a-2127-422b-91ae-364da2661108
https://www.xlabs.com.br/blog/?p=256