InduSoft Web Studio 7.1 SP2 Patch 4 이전 버전의 NTWebServer에 디렉터리 순회 취약점이 존재합니다. 원격 공격자는 명시되지 않은 웹 요청을 통해 APP 파일의 관리 암호를 읽고, 그 결과 임의 코드를 실행할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.