CVE-2022-45894
MEDIUM WAF: High
CVSS 6.5
Published: 2022-12-25
CWE-22 CWE-22
GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.
WAF Coverage Analysis
Path Traversal
High WAF Coverage
OWASP: A01:2021 Broken Access Control
930xxx - Local File Inclusion
Path Traversal
High WAF Coverage
OWASP: A01:2021 Broken Access Control
930xxx - Local File Inclusion
Affected Software
| Vendor | Product | Version |
|---|---|---|
| planetestream | planet_estream | up to 6.72.10.07 |
References
- sec-consult.com (Exploit, Third Party Advisory)