IPCheck Server Monitor Directory Traversal Vulnerability
BID:19473
CVE-2006-4140 |Info
IPCheck Server Monitor Directory Traversal Vulnerability
| Bugtraq ID: | 19473 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4140 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2006 12:00AM |
| Updated: | Jul 06 2007 08:07PM |
| Credit: | Tassi Raeburn is credited with the discovery of this vulnerability. |
| Vulnerable: |
Paessler IPCheck Server Monitor 5.3.2 .609 Paessler IPCheck Server Monitor 5.3 .508 Paessler IPCheck Server Monitor 5.2 .404 Paessler IPCheck Server Monitor 5.1 .342 Paessler IPCheck Server Monitor 4.3.1 .382 Paessler IPCheck Server Monitor 4.3.1 .368 |
| Not Vulnerable: |
Paessler IPCheck Server Monitor 5.3.3 .639 |
Discussion
IPCheck Server Monitor Directory Traversal Vulnerability
IPCheck Server Monitor is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
IPCheck Server Monitor 5.3.2.609 is vulnerable; other versions may also be affected.
IPCheck Server Monitor is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
IPCheck Server Monitor 5.3.2.609 is vulnerable; other versions may also be affected.
Exploit / POC
IPCheck Server Monitor Directory Traversal Vulnerability
Attackers may exploit this vulnerability through a browser.
The following proof of concept is available:
Attackers may exploit this vulnerability through a browser.
The following proof of concept is available:
Solution / Fix
IPCheck Server Monitor Directory Traversal Vulnerability
Solution:
The vendor has released IPCheck Server Monitor 5.3.3.639 to address this issue. Please contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
The vendor has released IPCheck Server Monitor 5.3.3.639 to address this issue. Please contact the vendor for details on obtaining and applying the appropriate updates.
References
IPCheck Server Monitor Directory Traversal Vulnerability
References:
References:
- IPCheck Server Monitor Homepage (Paessler)
- IPCheck History (Paessler)
- Directory Traversal vulnerability in IPCheck (Tassi Raeburn)