Add description

patch-1
Noam Rathaus 2021-08-29 09:42:18 +03:00
parent 86f3c08ba6
commit 5e27e5d528
1 changed files with 4 additions and 0 deletions

View File

@ -4,6 +4,10 @@ info:
name: Path traversal vulnerability in Microstrategy Web version 7
author: 0x_Akoko
severity: high
description: |
Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage)
allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /..
(slash dot dot) in a pathname used by a web application. NOTE: this is a deprecated product.
reference: https://www.exploit-db.com/exploits/45755
tags: microstrategy,lfi