Directory traversal vulnerability in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to read arbitrary files via a .. (dot dot) in the doc parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cruiseworks | Kynoslogic | 1.09c (including) | 1.09c (including) |
Cruiseworks | Kynoslogic | 1.09d (including) | 1.09d (including) |