7.5 CVE-2024-11978

Path Traversal
 

DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
https://nvd.nist.gov/vuln/detail/CVE-2024-11978

Categories

CWE-36 : Absolute Path Traversal
This allows attackers to traverse the file system to access files or directories that are outside of the restricted directory.

References


 

CPE

cpe start end


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
597 Absolute Path Traversal