Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Electronic_commerce_suite |
Icat |
3.0.0 |
3.0.0 |
References