Description
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
Remediation
References
Related Vulnerabilities
WordPress Plugin HTML5 Lyrics Karaoke Player Cross-Site Scripting (1.06)
WordPress Plugin Calendar Multiple Cross-Site Scripting Vulnerabilities (1.2.1)
SharePoint Improper Input Validation Vulnerability (CVE-2011-1989)
WordPress Plugin Captchinoo, Google recaptcha for admin login page Cross-Site Request Forgery (2.4)