TELE DATA Contact Management Server Directory Traversal Issue
Description
A vulnerability has been identified in TELE DATA Contact Management Server, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable web server. This issue is caused by an input validation error in the "command.html" script when processing the "FileName" parameter while "Cmd" is set to "SQL_Load", which could be exploited to disclose the contents of arbitrary files via a directory traversal attack.
Vulnerable Products
Vulnerable Software: TELE DATA Contact Management Server version 0.9 and prior