CVE-2016-10726

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-10726
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10726.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-10726
Aliases
Published
2018-07-10T11:29:00Z
Modified
2024-05-30T00:56:42.662203Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a colon before a pathname, as demonstrated by a themes/Reference/aa:etc/passwd URI.

References

Affected packages

Git / github.com/dspace/dspace

Affected ranges

Type
GIT
Repo
https://github.com/dspace/dspace
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

dspace-3.*

dspace-3.0
dspace-3.0-rc1
dspace-3.0-rc2
dspace-3.0-rc3
dspace-3.1
dspace-3.2
dspace-3.3
dspace-3.3-rc1
dspace-3.4
dspace-3.5