Permissions, Privileges, and Access Controls in CODESYS - CVE-2011-5058
Published: January 11, 2012 / Updated: August 11, 2020
CODESYS
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.
The CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the web root by specifying a non-existent directory using (backslash) characters in an HTTP GET request.