mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-14 15:08:03 +02:00
18 lines
873 B
Markdown
18 lines
873 B
Markdown
### [CVE-2018-2367](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-2367)
|
|
&color=blue)
|
|

|
|

|
|
|
|
### Description
|
|
|
|
ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|