SecurityReporter Directory Traversal Vulnerability And Authentication Bypass Vulnerability
BID:25027
Info
SecurityReporter Directory Traversal Vulnerability And Authentication Bypass Vulnerability
| Bugtraq ID: | 25027 |
| Class: | Unknown |
| CVE: |
CVE-2007-3986 CVE-2007-3985 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | Oliver Karow is credited with the discovery of this vulnerability. |
| Vulnerable: |
Secure Computing SecurityReporter 4.6.3 |
| Not Vulnerable: | |
Discussion
SecurityReporter Directory Traversal Vulnerability And Authentication Bypass Vulnerability
SecurityReporter is prone to an authentication-bypass vulnerability and a directory-traversal vulnerability.
An attacker can exploit these issues to fetch arbitrary files within the context of the webserver.
This issue affects SecurityReporter 4.6.3; other versions may also be affected.
SecurityReporter is prone to an authentication-bypass vulnerability and a directory-traversal vulnerability.
An attacker can exploit these issues to fetch arbitrary files within the context of the webserver.
This issue affects SecurityReporter 4.6.3; other versions may also be affected.
Exploit / POC
SecurityReporter Directory Traversal Vulnerability And Authentication Bypass Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
SecurityReporter Directory Traversal Vulnerability And Authentication Bypass Vulnerability
Solution:
The vendor released an update to address this issue. Please contact the vendor for information on how to obtain and apply this update.
Solution:
The vendor released an update to address this issue. Please contact the vendor for information on how to obtain and apply this update.
References
SecurityReporter Directory Traversal Vulnerability And Authentication Bypass Vulnerability
References:
References: