peter bassill · operator
$ cve CVE-2013-6720 JSON

CVE-2013-6720 EXPLOIT

5.5
MEDIUM · CVSS 2.0 · EPSS 28.6% (pctl 98)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions via a .. (dot dot) in the log parameter, as demonstrated using a crafted request for a customer-support file, as demonstrated by a log file.

Scoring

CVSS5.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
EPSS28.58% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2014-03-06
Last modified2026-06-17

Affected (1)

VendorProduct
ibmtealeaf cx

Public exploits

SourceTitleDate
exploit-dbIBM Tealeaf CX 8.8 - Remote OS Command Injection2014-03-26

References

→ the Explorer  ·  watch your stack  ·  NVD