Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GET request that uses encoded characters in the URL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wingate | Qbik | 2.1 (including) | 2.1 (including) |
Wingate | Qbik | 3.0 (including) | 3.0 (including) |
Wingate | Qbik | 4.0.1 (including) | 4.0.1 (including) |
Wingate | Qbik | 4.1_beta_a (including) | 4.1_beta_a (including) |