Unrated severityNVD Advisory· Published Aug 13, 2015· Updated May 6, 2026
CVE-2015-4666
CVE-2015-4666
Description
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- packetstormsecurity.com/files/132809/Xceedium-Xsuite-Command-Injection-XSS-Traversal-Escalation.htmlnvdExploit
- www.modzero.ch/advisories/MZ-15-02-Xceedium-Xsuite.txtnvdExploit
- support.ca.com/us/product-content/recommended-reading/security-notices/ca20180614-01--security-notice-for-ca-privileged-access-manager.htmlnvd
- www.exploit-db.com/exploits/37708/nvd
News mentions
0No linked articles in our index yet.