SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Splunk Lookup File Editing Directory Traversal

Category: WEB-ATTACKS      

In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1795


Relevant Information