EMC Navisphere Manager Directory Traversal And Information Disclosure Vulnerabilities
BID:14487
Info
EMC Navisphere Manager Directory Traversal And Information Disclosure Vulnerabilities
| Bugtraq ID: | 14487 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2357 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to an anonymous source. |
| Vulnerable: |
EMC Navisphere Manager 6.6 EMC Navisphere Manager 6.5 EMC Navisphere Manager 6.4.1 .0 EMC Navisphere Manager 6.4 |
| Not Vulnerable: |
EMC Navisphere Manager 6.6 .0.5.0 EMC Navisphere Manager 6.5.4 .0.0 EMC Navisphere Manager 6.4.8 .0.0 |
Discussion
EMC Navisphere Manager Directory Traversal And Information Disclosure Vulnerabilities
EMC Navisphere Manager is affected by directory traversal and information disclosure vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
A remote unauthorized user can disclose the contents of arbitrary local files through the use of directory traversal strings '../'. An attacker can also obtain the contents of arbitrary directories by appending a '.' to the end of a request. Exploitation of these vulnerabilities could lead to a loss of confidentiality and information disclosure.
EMC Navisphere Manager is affected by directory traversal and information disclosure vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
A remote unauthorized user can disclose the contents of arbitrary local files through the use of directory traversal strings '../'. An attacker can also obtain the contents of arbitrary directories by appending a '.' to the end of a request. Exploitation of these vulnerabilities could lead to a loss of confidentiality and information disclosure.
Exploit / POC
EMC Navisphere Manager Directory Traversal And Information Disclosure Vulnerabilities
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/../../../../../../../EMC/NAVISPHERE/common/log/navimon.log
http://www.example.com/.
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/../../../../../../../EMC/NAVISPHERE/common/log/navimon.log
http://www.example.com/.
Solution / Fix
EMC Navisphere Manager Directory Traversal And Information Disclosure Vulnerabilities
Solution:
The vendor has addressed this issue in the latest version of the affected application.
Solution:
The vendor has addressed this issue in the latest version of the affected application.
References
EMC Navisphere Manager Directory Traversal And Information Disclosure Vulnerabilities
References:
References: