3Com Network Supervisor Directory Traversal Vulnerability
BID:14715
Info
3Com Network Supervisor Directory Traversal Vulnerability
| Bugtraq ID: | 14715 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2020 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovery is credited to iDEFENSE Labs. |
| Vulnerable: |
3Com Network Supervisor 5.1 3Com Network Supervisor 5.0.2 3Com Network Supervisor 5.0 3Com Network Director 2.0 3Com Network Director 1.0 SP3 3Com Network Director 1.0 SP2 3Com Network Director 1.0 SP1 3Com Network Director 1.0 |
| Not Vulnerable: | |
Discussion
3Com Network Supervisor Directory Traversal Vulnerability
Network Supervisor is prone to a directory traversal vulnerability.
The application fails to properly sanitize input supplied through HTTP GET requests.
Exploitation of this vulnerability could lead to a loss of confidentiality as arbitrary files are disclosed to an attacker. It should be noted that all files on the affected drive can be disclosed by a successful attack.
Network Supervisor is prone to a directory traversal vulnerability.
The application fails to properly sanitize input supplied through HTTP GET requests.
Exploitation of this vulnerability could lead to a loss of confidentiality as arbitrary files are disclosed to an attacker. It should be noted that all files on the affected drive can be disclosed by a successful attack.
Exploit / POC
3Com Network Supervisor Directory Traversal Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
3Com Network Supervisor Directory Traversal Vulnerability
Solution:
The vendor has released updates to address this issue.
3Com Network Director 1.0 SP3
3Com Network Director 1.0 SP2
3Com Network Director 1.0 SP1
3Com Network Director 1.0
3Com Network Director 2.0
3Com Network Supervisor 5.1
Solution:
The vendor has released updates to address this issue.
3Com Network Director 1.0 SP3
-
3Com 3Com_network_director_v1_0_sp2_3_cu1.exe
http://support.3com.com/software/3Com_network_director_v1_0_sp2_3_cu1. exe
3Com Network Director 1.0 SP2
-
3Com 3Com_network_director_v1_0_sp2_3_cu1.exe
http://support.3com.com/software/3Com_network_director_v1_0_sp2_3_cu1. exe
3Com Network Director 1.0 SP1
-
3Com 3Com_network_director_v1_0_sp0_1_cu1.exe
http://support.3com.com/software/3Com_network_director_v1_0_sp0_1_cu1. exe
3Com Network Director 1.0
-
3Com 3Com_network_director_v1_0_sp0_1_cu1.exe
http://support.3com.com/software/3Com_network_director_v1_0_sp0_1_cu1. exe
3Com Network Director 2.0
-
3Com 3com_network_director_v2_0_cu1.exe
http://support.3com.com/software/3com_network_director_v2_0_cu1.exe
3Com Network Supervisor 5.1
-
3Com 3com_network_supervisor_v5_1_cu1.exe
http://support.3com.com/software/3com_network_supervisor_v5_1_cu1.exe
References
3Com Network Supervisor Directory Traversal Vulnerability
References:
References: