CollabNet Subversion Edge Management listViewItem LFI

The CollabNet Subversion Edge Management Frontend allows authenticated admins to read arbitrary local files via logfile “listViewItem” parameter of the “index” action. Fixed in version 5.0. Version 4.0.11 is affected.

Leave a Reply