Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Net_tools_pki_server | Network_associates | 1.0 (including) | 1.0 (including) |
Net_tools_pki_server | Network_associates | 1.0hotfix1 (including) | 1.0hotfix1 (including) |
Net_tools_pki_server | Network_associates | 1.0hotfix2 (including) | 1.0hotfix2 (including) |