The CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the web root by specifying a non-existent directory using (backslash) characters in an HTTP GET request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Codesys | 3ssoftware | 3.4-sp4 (including) | 3.4-sp4 (including) |