PNTresMailer Directory Traversal Vulnerability
BID:11767
Info
PNTresMailer Directory Traversal Vulnerability
| Bugtraq ID: | 11767 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2004 12:00AM |
| Updated: | Nov 26 2004 12:00AM |
| Credit: | "John Cobb" <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
pnTresMailer pnTresMailer 6.0 3 |
| Not Vulnerable: | |
Discussion
PNTresMailer Directory Traversal Vulnerability
pnTresMailer is reported susceptible to a directory traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input data.
This vulnerability can be exploited to retrieve arbitrary, potentially sensitive files from the hosting computer with the privileges of the web server. This may aid a malicious user in further attacks.
Version 6.03 of the application is reportedly affected by this vulnerability.
pnTresMailer is reported susceptible to a directory traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input data.
This vulnerability can be exploited to retrieve arbitrary, potentially sensitive files from the hosting computer with the privileges of the web server. This may aid a malicious user in further attacks.
Version 6.03 of the application is reportedly affected by this vulnerability.
Exploit / POC
PNTresMailer Directory Traversal Vulnerability
An example URI sufficient to exploit this vulnerability is provided:
http://www.example.com/codebrowserpntm.php?downloadfolder=pnTresMailer&filetodownload=../../../../etc/passwd
An example URI sufficient to exploit this vulnerability is provided:
http://www.example.com/codebrowserpntm.php?downloadfolder=pnTresMailer&filetodownload=../../../../etc/passwd
Solution / Fix
PNTresMailer Directory Traversal Vulnerability
Solution:
It has been reported that the vendor has resolved this issue, although this is not confirmed. Please see the attached references and contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that the vendor has resolved this issue, although this is not confirmed. Please see the attached references and contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PNTresMailer Directory Traversal Vulnerability
References:
References:
- pnTresMailer Home Page (pnTresMailer)
- PnTresMailer code browser 6.03 Vulnerabilities ("John Cobb"
)