ID:1421 - Exploit for Path traversal in Privileged Access Manager - CVE-2015-4666

 
Main Vulnerability Database Exploits ID:1421 - Exploit for Path traversal in Privileged Access Manager - CVE-2015-4666

ID:1421 - Exploit for Path traversal in Privileged Access Manager - CVE-2015-4666

Published: March 18, 2020


Vulnerability identifier: #VU13353
Vulnerability risk: Low
CVE-ID: CVE-2015-4666
CWE-ID: CWE-22
Exploitation vector: Remote access
Vulnerable software:
Privileged Access Manager

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to path traversal in the read_sessionlog.php script. A remote attacker can conduct directory traversal attacks and download sensitive information.

Remediation

Update to version 3.0.0 or later.