Keene Digital Media Server Directory Traversal Variant Vulnerability
BID:11057
Info
Keene Digital Media Server Directory Traversal Variant Vulnerability
| Bugtraq ID: | 11057 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2004 12:00AM |
| Updated: | Aug 26 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to "GulfTech Security" <[email protected]>. |
| Vulnerable: |
Keene Digital Media Server 1.0.2 |
| Not Vulnerable: | |
Discussion
Keene Digital Media Server Directory Traversal Variant Vulnerability
It is reported that DMS is susceptible to a directory traversal vulnerability.
The directory traversal issue is present upon requesting files outside the webroot of the application using hex encoded directory traversal character sequences to create a relative path to the target file.
This vulnerability will allow a remote attacker to retrieve potentially sensitive files, possibly aiding them in further system compromise.
Version 1.0.2 of the software is reported vulnerable to this issue. Other versions may also be affected.
It is reported that DMS is susceptible to a directory traversal vulnerability.
The directory traversal issue is present upon requesting files outside the webroot of the application using hex encoded directory traversal character sequences to create a relative path to the target file.
This vulnerability will allow a remote attacker to retrieve potentially sensitive files, possibly aiding them in further system compromise.
Version 1.0.2 of the software is reported vulnerable to this issue. Other versions may also be affected.
Exploit / POC
Keene Digital Media Server Directory Traversal Variant Vulnerability
There is no exploit required, the following examples are available:
http://www.example.com/%2E%2E%5Csystem.log
http://www.example.com/%2E%2E\system.log
There is no exploit required, the following examples are available:
http://www.example.com/%2E%2E%5Csystem.log
http://www.example.com/%2E%2E\system.log
Solution / Fix
Keene Digital Media Server Directory Traversal Variant Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Keene Digital Media Server Directory Traversal Variant Vulnerability
References:
References:
- Digital Media Server Home Page (Keene)
- Keene Digital Media Server Directory Traversal ("GulfTech Security"
)