CVE-2014-5370 – Arbitrary File Retrieval + Deletion In New Atlanta BlueDragon CFChart Servlet

Posted by Portcullis Advisories on Apr 17

Vulnerability title: Arbitrary File Retrieval + Deletion In New Atlanta BlueDragon CFChart Servlet
CVE: CVE-2014-5370
Vendor: New Atlanta
Product: BlueDragon CFChart Servlet
Affected version: 7.1.1.17759
Fixed version: 7.1.1.18527
Reported by: Mike Westmacott
Details:

The CFChart servlet of BlueDragon (component com.naryx.tagfusion.cfm.cfchartServlet) is vulnerable to arbitrary file
retrieval due to a directory traversal vulnerability. In…

Leave a Reply