PacketTrap pt360 Tool Suite TFTP Server Directory Traversal Vulnerability
BID:28078
Info
PacketTrap pt360 Tool Suite TFTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 28078 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1310 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 03 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | princeofnigeria and r@b13$ are credited with the discovery of this vulnerability. |
| Vulnerable: |
PacketTrap Networks pt360 Tool Suite TFTP Server 1.1.33.1 |
| Not Vulnerable: | |
Discussion
PacketTrap pt360 Tool Suite TFTP Server Directory Traversal Vulnerability
PacketTrap pt360 Tool Suite TFTP server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows attackers to access arbitrary files outside of the TFTP server root directory. This can expose sensitive information that could help the attacker launch further attacks, including overwriting system files, which could lead to a complete compromise of the computer.
PacketTrap pt360 Tool Suite TFTP server 1.1.33.1 is vulnerable; other versions may also be affected.
PacketTrap pt360 Tool Suite TFTP server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows attackers to access arbitrary files outside of the TFTP server root directory. This can expose sensitive information that could help the attacker launch further attacks, including overwriting system files, which could lead to a complete compromise of the computer.
PacketTrap pt360 Tool Suite TFTP server 1.1.33.1 is vulnerable; other versions may also be affected.
Exploit / POC
PacketTrap pt360 Tool Suite TFTP Server Directory Traversal Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
PacketTrap pt360 Tool Suite TFTP Server Directory Traversal Vulnerability
Solution:
The vendor has released patch #3302 to address this issue. Please contact the vendor for information on obtaining and applying the patch.
Solution:
The vendor has released patch #3302 to address this issue. Please contact the vendor for information on obtaining and applying the patch.
References
PacketTrap pt360 Tool Suite TFTP Server Directory Traversal Vulnerability
References:
References: