NONE · 0

CVE-2012-10061

Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files from the server’s filesystem. The vulnerability ex...

Vulnerability Description

Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files from the server’s filesystem. The vulnerability exists in the HTTP interface on port 4444, where the endpoint /file/ fails to properly sanitize user-supplied input. Attackers can traverse directories and access sensitive files outside the intended web root.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-10061?

CVE-2012-10061 is a documented vulnerability. Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files from the server’s filesystem. The vulnerability ex...

How severe is CVE-2012-10061?

CVSS scoring is not yet available for CVE-2012-10061. Check NVD for updates.

Is there a patch for CVE-2012-10061?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.