Cruiseworks Cws.EXE Doc Directory Traversal Vulnerability
BID:20698
Info
Cruiseworks Cws.EXE Doc Directory Traversal Vulnerability
| Bugtraq ID: | 20698 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2006 12:00AM |
| Updated: | Oct 24 2006 11:33PM |
| Credit: | Tan Chew Keong is credited with the discovery of this vulnerability. |
| Vulnerable: |
Cruiseworks Cruiseworks 1.09.d Cruiseworks Cruiseworks 1.09.c |
| Not Vulnerable: |
Cruiseworks Cruiseworks 1.09.e |
Discussion
Cruiseworks Cws.EXE Doc Directory Traversal Vulnerability
Cruiseworks is prone to a directory-traversal vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.
Cruiseworks 1.09c and 1.09d are reported vulnerable; other versions may be affected as well.
Cruiseworks is prone to a directory-traversal vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.
Cruiseworks 1.09c and 1.09d are reported vulnerable; other versions may be affected as well.
Exploit / POC
Cruiseworks Cws.EXE Doc Directory Traversal Vulnerability
Attackers can exploit this issue via a web client.
An example URI is as follows:
http://www.example.com/Scripts/cruise/cws.exe?doc=../data/system.wdb
Note: the above URI requires a login to the application.
Attackers can exploit this issue via a web client.
An example URI is as follows:
http://www.example.com/Scripts/cruise/cws.exe?doc=../data/system.wdb
Note: the above URI requires a login to the application.
Solution / Fix
Cruiseworks Cws.EXE Doc Directory Traversal Vulnerability
Solution:
The vendor has released version 1.09e to address this issue.
Cruiseworks Cruiseworks 1.09.d
Solution:
The vendor has released version 1.09e to address this issue.
Cruiseworks Cruiseworks 1.09.d
-
Cruiseworks Cruiseworks 1.09e
http://www.kynos.co.jp/cruise/cws/home.shtml
References
Cruiseworks Cws.EXE Doc Directory Traversal Vulnerability
References:
References:
- CruiseWorks Directory Traversal and Buffer Overflow Vulnerabilities (Tan Chew Kong)
- Cruiseworks Homepage (Cruiseworks)