4D WebStar Symbolic Link Vulnerability
BID:10714
Info
4D WebStar Symbolic Link Vulnerability
| Bugtraq ID: | 10714 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 13 2004 12:00AM |
| Updated: | Jul 13 2004 12:00AM |
| Credit: | Discovery of this issue is credited to @stake inc. |
| Vulnerable: |
4D WebSTAR 5.3.2 4D WebSTAR 5.3.1 4D WebSTAR 5.3 4D WebSTAR 5.2.4 4D WebSTAR 5.2.3 4D WebSTAR 5.2.2 4D WebSTAR 5.2.1 4D WebSTAR 5.2 4D WebSTAR 4.0 |
| Not Vulnerable: |
4D WebSTAR 5.3.3 |
Discussion
4D WebStar Symbolic Link Vulnerability
4D WebStar is reportedly vulnerable to a symbolic link vulnerability. This issue is due to a design error that causes the application to open files without properly verifying their existence or their absolute location.
Successful exploitation of this issue will allow an attacker to write to arbitrary files writable by the affected application, facilitating privilege escalation.
4D WebStar is reportedly vulnerable to a symbolic link vulnerability. This issue is due to a design error that causes the application to open files without properly verifying their existence or their absolute location.
Successful exploitation of this issue will allow an attacker to write to arbitrary files writable by the affected application, facilitating privilege escalation.
Exploit / POC
4D WebStar Symbolic Link Vulnerability
It has been reported that an exploit has been developed to leverage this issue, however it is not known to be publicly circulating.
It has been reported that an exploit has been developed to leverage this issue, however it is not known to be publicly circulating.
Solution / Fix
4D WebStar Symbolic Link Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
4D WebSTAR 5.2
4D WebSTAR 5.2.1
4D WebSTAR 5.2.2
4D WebSTAR 5.2.3
4D WebSTAR 5.2.4
4D WebSTAR 5.3
4D WebSTAR 5.3.1
4D WebSTAR 5.3.2
Solution:
The vendor has released an upgrade dealing with this issue.
4D WebSTAR 5.2
4D WebSTAR 5.2.1
4D WebSTAR 5.2.2
4D WebSTAR 5.2.3
4D WebSTAR 5.2.4
4D WebSTAR 5.3
4D WebSTAR 5.3.1
4D WebSTAR 5.3.2
References
4D WebStar Symbolic Link Vulnerability
References:
References:
- 4D Inc. Homepage (4D Inc.)
- 4D WebSTAR Product Page (4D Inc.)
- @stake advisory: WebSTAR (5.3.2 and below) Multiple Vulnerabilities (@stake)