CVE-2014-0358
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 6.2%
from disclosure to weapon0 days
Published on NVDApr 15
1st PoCApr 14
exploitation probability
6.2%top 7% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the file parameter in a getUpgradeStatus action to servlet/MGConfigData, (2) the download parameter in a download action to servlet/MGConfigData, (3) the download parameter in a port_svc action to servlet/MGConfigData, (4) the file parameter in a getfile action to servlet/Installer, or (5) the binfile parameter to servlet/MGConfigData.
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/39145exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/39143exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/39142⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://www.kb.cert.org/vuls/id/657622