Vulnerabilities
Vulnerable Software
Tryton:  >> Tryton  >> 3.2.9  Security Vulnerabilities
file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root name but with a suffix" attack. NOTE: This vulnerability exists because of an incomplete fix for CVE-2016-1242.
CVSS Score
5.3
EPSS Score
0.003
Published
2017-04-04
file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.
CVSS Score
4.4
EPSS Score
0.002
Published
2016-09-07
Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remote authenticated users to discover user password hashes via unspecified vectors.
CVSS Score
5.3
EPSS Score
0.002
Published
2016-09-07


Contact Us

Shodan ® - All rights reserved