Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the l parameter, related to an "Insecure Direct Object Reference vulnerability." Per: http://www.ventuneac.net/security-advisories/MVSA-10-008
Affected Versions
IBM Proventia Network Mail Security System - virtual appliance (firmware 1.6)
Publication date: Tue, 14 Sep 2010 22:00:00 +0000