An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HXorux Lpar2rrd
APPXorux≤ 8.04
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
Related vulnerabilities
CVE-2021-42371CRITICAL9.8PL ✓same product
Hardkodowane konto systemowe w XoruX LPAR2RRD i STOR2RRD
CVE-2020-24032CRITICAL9.8PL ✓same product
Command injection w XoruX LPAR2RRD i STOR2RRD przez parametr strefy czasowej
CVE-2014-4981CRITICAL9.8PL ✓same product
Command Injection w LPAR2RRD — zdalne wykonanie poleceń systemowych
CVE-2014-4982CRITICAL9.8PL ✓same product
Command injection w Xorux LPAR2RRD — zdalne wykonanie poleceń
CVE-2021-42370HIGH7.5same product
A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext informa...