Back to search
CVE-2017-9812
Published: Jul 17, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary files with kluser privileges.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20170628 [CORE-2017-0003] - Kaspersky Anti-Virus File Server Multiple Vulnerabilities
mailing-list
x_refsource_FULLDISC
99330
vdb-entry
x_refsource_BID
1038798
vdb-entry
x_refsource_SECTRACK
42269
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now