Documentum Products 'dmclTrace.jsp' Arbitrary File Overwrite Vulnerability
BID:27632
Info
Documentum Products 'dmclTrace.jsp' Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 27632 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0656 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Pablo Gaston Milano is credited with the discovery of this vulnerability. |
| Vulnerable: |
Documentum WebTop 5.3 .317 Documentum WebTop 5.2.5 SP2 Documentum WebTop 5.2.5 Documentum Documentum Administrator 5.3 .313 Documentum Documentum Administrator 5.2.5 SP2 Documentum Documentum Administrator 5.2.5 Documentum Documentum Administrator 4.2.8 |
| Not Vulnerable: |
Documentum WebTop 5.3 SP4 Documentum Documentum Administrator 5.3 SP4 |
Discussion
Documentum Products 'dmclTrace.jsp' Arbitrary File Overwrite Vulnerability
Multiple Documentum products are prone to a vulnerability that could permit an attacker to overwrite arbitrary files because the software fails to verify user-supplied input.
A remote attacker can exploit this issue to overwrite arbitrary files on the victim's computer. This can allow the attacker to upload and execute arbitrary scripts in the context of the user running the affected application.
This issue affects the following:
Documentum Administrator 5.3.0.313
Documentum Webtop 5.3.0.317
Other Documentum applications and versions may also be affected.
Multiple Documentum products are prone to a vulnerability that could permit an attacker to overwrite arbitrary files because the software fails to verify user-supplied input.
A remote attacker can exploit this issue to overwrite arbitrary files on the victim's computer. This can allow the attacker to upload and execute arbitrary scripts in the context of the user running the affected application.
This issue affects the following:
Documentum Administrator 5.3.0.313
Documentum Webtop 5.3.0.317
Other Documentum applications and versions may also be affected.
Exploit / POC
Documentum Products 'dmclTrace.jsp' Arbitrary File Overwrite Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
Documentum Products 'dmclTrace.jsp' Arbitrary File Overwrite Vulnerability
Solution:
The vendor released Documentum Administrator 5.3 SP4 and Documentum WebTop 5.3 SP4 to address this issue. Please see the references for more information.
Solution:
The vendor released Documentum Administrator 5.3 SP4 and Documentum WebTop 5.3 SP4 to address this issue. Please see the references for more information.
References
Documentum Products 'dmclTrace.jsp' Arbitrary File Overwrite Vulnerability
References:
References:
- CYBSEC Security Advisory: Arbitrary file overwrite in Documentum Administrator (CYBSEC Advisories)
- Documentum Administrator (EMC)
- Documentum Webtop Homepage (EMC)
- CYBSEC Security Advisory: Arbitrary file overwrite in Documentum Administrator (CYBSEC Advisories
)