Cybozu Multiple Products Directory Traversal Vulnerability
BID:19733
Info
Cybozu Multiple Products Directory Traversal Vulnerability
| Bugtraq ID: | 19733 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 28 2006 12:00AM |
| Updated: | Sep 05 2006 08:13PM |
| Credit: | Isaac Dawson is credited with discovery of this issue. Tan Chew Keong also discovered this issue independently. |
| Vulnerable: |
Cybozu Share360 2.5 Build 0.2 Cybozu Office 6.5 Cybozu Garoon 1 Cybozu AG Pocket 0 Cybozu AG Mailwise 0 Cybozu AG 0 |
| Not Vulnerable: |
Cybozu Share360 2.5 Build 0.3 Cybozu Office 6.6 Build 1.3 Cybozu Garoon 1.5(4.1) Cybozu AG Pocket 5.2 Build 0.8 Cybozu AG Mailwise 3.0 Build 0.3 Cybozu AG 1.2 Build 1.5 |
Discussion
Cybozu Multiple Products Directory Traversal Vulnerability
Multiple Cybozu Products are prone to a directory-traversal vulnerability because they fail to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected applications. Information obtained may aid in further attacks.
Multiple Cybozu Products are prone to a directory-traversal vulnerability because they fail to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected applications. Information obtained may aid in further attacks.
Exploit / POC
Cybozu Multiple Products Directory Traversal Vulnerability
Attackers may exploit this vulnerability via a web client.
The following proof of concept is available:
Attackers may exploit this vulnerability via a web client.
The following proof of concept is available:
Solution / Fix
Cybozu Multiple Products Directory Traversal Vulnerability
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Cybozu Office 6.5
Cybozu AG Mailwise 0
Cybozu AG 0
Cybozu AG Pocket 0
Cybozu Garoon 1
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Cybozu Office 6.5
-
Cybozu Office 6.6 (Build 1.3)
http://office.cybozu.co.jp/cb6/download/
Cybozu AG Mailwise 0
-
Cybozu Mailwise 3.0(0.3)
http://crm.cybozu.co.jp/download/
Cybozu AG 0
-
Cybozu AG 1.2(1.5)
http://cybozu.co.jp/download/oldfiles.html#ag
Cybozu AG Pocket 0
-
Cybozu AG Pocket 5.2(0.8)
http://cybozu.co.jp/download/oldfiles.html#agpt
Cybozu Garoon 1
-
Cybozu Garoon 1.5(4.1)
http://cybozu.co.jp/products/dl/notice_060825/download.html#gr1
References
Cybozu Multiple Products Directory Traversal Vulnerability
References:
References:
- Advisory (Cybozu)
- Cybozu Home Page (Cybozu)
- Cybozu Products Arbitrary File Retrieval Vulnerability (Tan Chew Keong)