NetGain Systems Enterprise Manager CVE-2017-16591 Directory Traversal Vulnerability
BID:102318
Info
NetGain Systems Enterprise Manager CVE-2017-16591 Directory Traversal Vulnerability
| Bugtraq ID: | 102318 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-16591 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2017 12:00AM |
| Updated: | Dec 13 2017 12:00AM |
| Credit: | rgod |
| Vulnerable: |
NetGain Systems Enterprise Manager 0 |
| Not Vulnerable: |
NetGain Systems Enterprise Manager 7.2.766 |
Discussion
NetGain Systems Enterprise Manager CVE-2017-16591 Directory Traversal Vulnerability
NetGain Systems Enterprise Manager is prone to a directory-traversal vulnerability.
An attacker can exploit this issue using directory-traversal characters ('../') to access or read arbitrary files that contain sensitive information or to access files outside of the restricted directory to obtain sensitive information and perform other attacks.
NetGain Systems Enterprise Manager is prone to a directory-traversal vulnerability.
An attacker can exploit this issue using directory-traversal characters ('../') to access or read arbitrary files that contain sensitive information or to access files outside of the restricted directory to obtain sensitive information and perform other attacks.
Exploit / POC
NetGain Systems Enterprise Manager CVE-2017-16591 Directory Traversal Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
NetGain Systems Enterprise Manager CVE-2017-16591 Directory Traversal Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
NetGain Systems Enterprise Manager CVE-2017-16591 Directory Traversal Vulnerability
References:
References: