Advantech WebAccess openWidget Script Path Traversal Remote File Disclosure
Medium Nessus Plugin ID 88839
SynopsisThe remote host has a web application that is affected by a file disclosure vulnerability.
DescriptionThe Advantech WebAccess web server running on the remote host is affected by a file disclosure vulnerability in the WebAccess Dashboard Viewer due to a failure to properly sanitize user-supplied input to the openWidget script. An unauthenticated, remote attacker can exploit this, via path traversal, to read the content of arbitrary files on the WebAccess server.
Note that this Advantech WebAccess web server is reportedly affected by other vulnerabilities as well; however, Nessus has not tested for these.
SolutionUpgrade to Advantech WebAccess version 8.1-2015.12.30 or later.