The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft Windows. Depending on how a web application uses and configures TIFF Server, a remote attacker may be able to enumerate files or directories, traverse directories, bypass authentication, or access restricted files.
References
Configurations
History
No history.
Information
Published : 2023-11-30 18:15
Updated : 2024-11-21 08:43
NVD link : CVE-2023-6352
Mitre link : CVE-2023-6352
CVE.ORG link : CVE-2023-6352
JSON object : View
Products Affected
aquaforest
- tiff_server
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')