An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server is running) by triggering an invalid path permission error. This bypasses the fakepath protection mechanism.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-06-02T13:52:28

Updated: 2020-06-02T13:52:28

Reserved: 2020-05-20T00:00:00


Link: CVE-2020-13227

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-06-02T14:15:10.567

Modified: 2020-06-02T15:12:25.253


Link: CVE-2020-13227

JSON object: View

cve-icon Redhat Information

No data.

CWE