Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) attack on the page parameter.
| Software | From | Fixed in |
|---|---|---|
| sambar / sambar_server | 5.0-beta2 | 5.0-beta2.x |
| sambar / sambar_server | 5.0-beta4 | 5.0-beta4.x |
| sambar / sambar_server | 4.4 | 4.4.x |
| sambar / sambar_server | 5.0-beta1 | 5.0-beta1.x |
| sambar / sambar_server | 5.0-beta3 | 5.0-beta3.x |