Title: WebTeacher WebData File Import Vulnerability
Severity: MODERATE
Description:
WebTeacher WebData is a database program deployable across the World Wide Web.
Any user who has a valid member account on WebData is capable of importing any accessible file on the system to the WebData directory. This would ensure that the user could access any file below the root directory by browsing through the database even if it has been specified that WebData would only serve up certain files. The import function should normally only allow user uploaded files into the database, however it will permit any file to be imported onto the server.
Affected Products:
- WebTeacher WebData 2.2.0
References:
- WebTeacher: WebData Product Homepage
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.