A classic directory traversal condition exists within the Sentinel Protection Server. By sending in an HTTP GET request with a path of a file proceeded by and escaped traversal sequence, an attacker can leverage an arbitrary file access condition on the affected system. Sentinel Protection Server version 7.1 is affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/61243/sentinel-traverse.txt
Source: https://packetstormsecurity.com/files/61243/sentinel-traverse.txt.html

