Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GET request that uses encoded characters in the URL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Wingate | Qbik | 2.1 (including) | 2.1 (including) |
| Wingate | Qbik | 3.0 (including) | 3.0 (including) |
| Wingate | Qbik | 4.0.1 (including) | 4.0.1 (including) |
| Wingate | Qbik | 4.1_beta_a (including) | 4.1_beta_a (including) |