SpiderControl SCADA Web Server CVE-2017-12694 Directory Traversal Vulnerability
BID:100456
CVE-2017-12694 |Info
SpiderControl SCADA Web Server CVE-2017-12694 Directory Traversal Vulnerability
| Bugtraq ID: | 100456 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-12694 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2017 12:00AM |
| Updated: | Aug 22 2017 12:00AM |
| Credit: | Karn Ganeshen from Trend Micro�??s Zero Day Initiative (ZDI) |
| Vulnerable: |
SpiderControl SCADA Web Server 0 |
| Not Vulnerable: |
SpiderControl SCADA Web Server 2.02.0100 |
Discussion
SpiderControl SCADA Web Server CVE-2017-12694 Directory Traversal Vulnerability
SpiderControl SCADA Web Server is prone to a directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to read arbitrary files in the context of the application. This may aid in further attacks.
SpiderControl SCADA Web Server is prone to a directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to read arbitrary files in the context of the application. This may aid in further attacks.
Exploit / POC
SpiderControl SCADA Web Server CVE-2017-12694 Directory Traversal Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.