Directory Traversal Vulnerabilities in Splunk 4.x before 4.2.5 (SPL-45243)

Directory Traversal Vulnerabilities in Splunk 4.x before 4.2.5 (SPL-45243)

CVE-2011-4643 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:N/A:N

Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitrary files via a .. (dot dot) in a URI to (1) Splunk Web or (2) the Splunkd HTTP Server, aka SPL-45243.

Learn more about our Web App Pen Testing.