| CVE ID | CVE-2015-4031 |
| CVSS SCORE | 10.0, AV:N/AC:L/Au:N/C:C/I:C/A:C |
| AFFECTED VENDORS |
Visual Mining |
| AFFECTED PRODUCTS |
NetCharts Server |
| VULNERABILITY DETAILS |
The specific flaw exists within the development installation. The saveFile.jsp page does not properly check for directory traversal, allowing an attacker to overwrite any file on the system. An attacker could leverage this to execute arbitrary code in the context of SYSTEM. |
| ADDITIONAL DETAILS |
9/11/2014 - ZDI disclosed report to Visual Mining Technical Support Team. -- Mitigation:
|
| DISCLOSURE TIMELINE |
|
| CREDIT | bart |