Paul Smith Computer Services VCAP Calendar Server Directory Traversal Vulnerability
BID:19958
Info
Paul Smith Computer Services VCAP Calendar Server Directory Traversal Vulnerability
| Bugtraq ID: | 19958 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2006 12:00AM |
| Updated: | Sep 12 2006 07:07PM |
| Credit: | securma massine <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Paul Smith Computer Services vCAP Calendar Server 1.9 Beta |
| Not Vulnerable: | |
Discussion
Paul Smith Computer Services VCAP Calendar Server Directory Traversal Vulnerability
vCAP Calendar Server is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
vCAP Calendar Server 1.9.0 Beta and prior versions are vulnerable to this issue.
vCAP Calendar Server is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
vCAP Calendar Server 1.9.0 Beta and prior versions are vulnerable to this issue.
Exploit / POC
Paul Smith Computer Services VCAP Calendar Server Directory Traversal Vulnerability
Attackers may exploit this vulnerability via a web client.
The following proof of concept is available:
Attackers may exploit this vulnerability via a web client.
The following proof of concept is available:
Solution / Fix
Paul Smith Computer Services VCAP Calendar Server Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Paul Smith Computer Services VCAP Calendar Server Directory Traversal Vulnerability
References:
References:
- Home Page (Paul Smith Computer Services)
- vCAP calendar server Multiple vulnerability (securma massine
)