CVE-2016-8205
critical · 9.8A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.
9.8
CVSS
13.0%
EPSS (exploit prob.)
96th
EPSS percentile
2017-01-14
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| brocade | network_advisor | <= 14.0.2 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/95694
- http://www.zerodayinitiative.com/advisories/ZDI-17-050
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03785en_us
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-178
- http://www.securityfocus.com/bid/95694
- http://www.zerodayinitiative.com/advisories/ZDI-17-050
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03785en_us
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-178
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-8205