CVE-2016-4314 | WSO2 Carbon 4.4.5 downloadgz-ajaxprocessor.jsp logFile path traversal (EDB-40240 / BID-92473)
A vulnerability was found in WSO2 Carbon 4.4.5. It has been classified as problematic. Affected is an unknown function of the file downloadgz-ajaxprocessor.jsp. The manipulation of the argument logFile leads to path traversal.
This vulnerability is traded as CVE-2016-4314. It is possible to launch the attack remotely. Furthermore, there is an exploit available.