GE Fanuc Proficy Portal Remote Script Code Execution Vulnerability
BID:27446
Info
GE Fanuc Proficy Portal Remote Script Code Execution Vulnerability
| Bugtraq ID: | 27446 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0175 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2008 12:00AM |
| Updated: | Nov 04 2008 05:55PM |
| Credit: | Eyal Udassin of C4 is credited with the discovery of this issue. |
| Vulnerable: |
GE Fanuc Proficy Real-Time Information Portal 2.6 GE Fanuc Proficy Real-Time Information Portal 0 |
| Not Vulnerable: | |
Discussion
GE Fanuc Proficy Portal Remote Script Code Execution Vulnerability
Proficy Real Time Information Portal is prone to a remote script-code-execution vulnerability because the application fails to properly sanitize user-supplied input.
A successful exploit can allow an attacker to upload arbitrary scripts and execute them in the context of the application.
Proficy Real Time Information Portal 2.6 is vulnerable; other versions may also be affected.
Proficy Real Time Information Portal is prone to a remote script-code-execution vulnerability because the application fails to properly sanitize user-supplied input.
A successful exploit can allow an attacker to upload arbitrary scripts and execute them in the context of the application.
Proficy Real Time Information Portal 2.6 is vulnerable; other versions may also be affected.
Exploit / POC
GE Fanuc Proficy Portal Remote Script Code Execution Vulnerability
The following Metasploit module has been released:
The following Metasploit module has been released:
Solution / Fix
GE Fanuc Proficy Portal Remote Script Code Execution Vulnerability
Solution:
The vendor indicates that this issue will be addressed in a Software Improvement Module (SIM) on approximately February 15, 2008. Please contact the vendor for details about obtaining and applying the pending release.
Solution:
The vendor indicates that this issue will be addressed in a Software Improvement Module (SIM) on approximately February 15, 2008. Please contact the vendor for details about obtaining and applying the pending release.
References
GE Fanuc Proficy Portal Remote Script Code Execution Vulnerability
References:
References:
- GE Fanuc Product Vulnerabilities (US-CERT)
- KB12460 Security Issue: GE Fanuc Proficy Real-Time Information Portal allows arb (GE Fanuc)
- Proficy Information Portal Homepage (GE Fanuc)
- C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Arbitrary File Up ("Eyal Udassin"
) - Re: C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Arbitrary F ([email protected])
- Vulnerability Note VU#339345 GE Fanuc Proficy Information Portal allows arbitrar (US-CERT)