← Back to CVE List

CVE-2016-6126

Published: 2017-02-01T20:59Z
Last Modified: 2024-11-21T02:55Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt