CVE-2014-0358: Xangati Software Release
High severity, CVSS 7.8. EPSS: 5.9% chance of exploitation in the next 30 days.
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the file parameter in a getUpgradeStatus action to servlet/MGConfigData, (2) the download parameter in a download action to servlet/MGConfigData, (3) the download parameter in a port_svc action to servlet/MGConfigData, (4) the file parameter in a getfile action to servlet/Installer, or (5) the binfile parameter to servlet/MGConfigData.
Affected products
- Xangati Xangati Software Release: affected versions not specified
- Xangati Xangati Xnr: affected versions not specified
Published 2014-04-15. Last modified 2026-06-17.