[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*


oval:org.secpod.oval:def:24268
The host is installed with Elasticsearch 1.4.x before 1.4.5 or 1.5.x before 1.5.2 and is prone to a directory traversal vulnerability. A flaw is present in the application, which fails to handle unspecified vectors. Successful exploitation could allow attackers to read arbitrary files.

oval:org.secpod.oval:def:602068
John Heasman discovered that the site plugin handling of the Elasticsearch search engine was susceptible to directory traversal.

oval:org.secpod.oval:def:24270
The host is installed with Elasticsearch 1.4.x before 1.4.5 or 1.5.x before 1.5.2 and is prone to a directory traversal vulnerability. A flaw is present in the application, which fails to handle unspecified vectors. Successful exploitation could allow attackers to read arbitrary files.

CPE    2
cpe:/a:elasticsearch:elasticsearch:1.5.0
cpe:/a:elasticsearch:elasticsearch:1.5.1
CWE    1
CWE-22
*CVE
CVE-2015-3337

© SecPod Technologies