Symantec Backup Exec System Recovery Manager FileUpload Class Unauthorized File Upload Vulnerability
BID:27487
Info
Symantec Backup Exec System Recovery Manager FileUpload Class Unauthorized File Upload Vulnerability
| Bugtraq ID: | 27487 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0457 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2008 12:00AM |
| Updated: | Feb 07 2008 10:36PM |
| Credit: | Titon of BastardLabs, working with 3COM/TippingPoint, and the Zero Day Initiative is credited with the discovery of this issue. |
| Vulnerable: |
Symantec Backup Exec System Recovery Manager 7.0.1 Symantec Backup Exec System Recovery Manager 7.0 |
| Not Vulnerable: |
Symantec Backup Exec System Recovery Manager 7.0.3 |
Discussion
Symantec Backup Exec System Recovery Manager FileUpload Class Unauthorized File Upload Vulnerability
Symantec Backup Exec System Recovery Manager is prone to a vulnerability that allows arbitrary unauthorized files to be uploaded to any location on the affected server.
This issue resides in the Symantec LiveState Apache Tomcat server. Attackers can leverage it to execute arbitrary code with SYSTEM-level privileges and completely compromise affected computers.
Symantec Backup Exec System Recovery Manager is prone to a vulnerability that allows arbitrary unauthorized files to be uploaded to any location on the affected server.
This issue resides in the Symantec LiveState Apache Tomcat server. Attackers can leverage it to execute arbitrary code with SYSTEM-level privileges and completely compromise affected computers.
Exploit / POC
Symantec Backup Exec System Recovery Manager FileUpload Class Unauthorized File Upload Vulnerability
Attackers can exploit this issue by submitting a specially crafted HTTP POST request to the affected computer.
The following proof-of-concept code is available:
Attackers can exploit this issue by submitting a specially crafted HTTP POST request to the affected computer.
The following proof-of-concept code is available:
Solution / Fix
Symantec Backup Exec System Recovery Manager FileUpload Class Unauthorized File Upload Vulnerability
Solution:
Symantec released security advisory SYM08-001 and Backup Exec System Recovery Manager 7.0.3 to address this issue. Please see the references for more information.
Solution:
Symantec released security advisory SYM08-001 and Backup Exec System Recovery Manager 7.0.3 to address this issue. Please see the references for more information.