VulnerabilityModified
CVE-2011-0329
Directory traversal vulnerability in the GetData method in the Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 allows remote attackers to read arbitrary files via directory traversal sequences in the fileID parameter.
MEDIUM 5.0EPSS 1.58%
Does this matter?
Lower severity and a low EPSS score (1.58%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the GetData method in the Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 allows remote attackers to read arbitrary files via directory traversal sequences in the fileID parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.58% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- dell/dellsystemlite.scanner activex control
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://secunia.com/advisories/42880Vendor Advisory
- http://secunia.com/secunia_research/2011-10/Vendor Advisory
- http://www.securityfocus.com/bid/46443
- http://www.securitytracker.com/id?1025094
- http://secunia.com/advisories/42880Vendor Advisory
- http://secunia.com/secunia_research/2011-10/Vendor Advisory
- http://www.securityfocus.com/bid/46443
- http://www.securitytracker.com/id?1025094
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.