Timbuktu Pro File Upload and Log Input Manipulation Vulnerabilities
BID:28081
Info
Timbuktu Pro File Upload and Log Input Manipulation Vulnerabilities
| Bugtraq ID: | 28081 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1117 CVE-2008-1118 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2008 12:00AM |
| Updated: | Mar 12 2008 12:31AM |
| Credit: | Sebastian Muñiz is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Motorola Timbuktu 8.6.5 |
| Not Vulnerable: | |
Discussion
Timbuktu Pro File Upload and Log Input Manipulation Vulnerabilities
Timbuktu Pro is prone to an arbitrary-file-upload vulnerability and a vulnerability that allows attackers to disrupt the logging of events.
An attacker can exploit these issues to upload arbitrary files and prevent the logging of events. This may lead to other attacks.
Timbuktu Pro 8.6.5 for Windows is vulnerable; other versions running on different platforms may also be affected.
The file-upload vulnerability may be related to BID 25453 (Motorola Timbuktu Pro Directory Traversal Vulnerability).
Timbuktu Pro is prone to an arbitrary-file-upload vulnerability and a vulnerability that allows attackers to disrupt the logging of events.
An attacker can exploit these issues to upload arbitrary files and prevent the logging of events. This may lead to other attacks.
Timbuktu Pro 8.6.5 for Windows is vulnerable; other versions running on different platforms may also be affected.
The file-upload vulnerability may be related to BID 25453 (Motorola Timbuktu Pro Directory Traversal Vulnerability).
Exploit / POC
Timbuktu Pro File Upload and Log Input Manipulation Vulnerabilities
Attackers can use readily available tools to exploit these issues.
The following exploit code is available:
Attackers can use readily available tools to exploit these issues.
The following exploit code is available:
Solution / Fix
Timbuktu Pro File Upload and Log Input Manipulation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Timbuktu Pro File Upload and Log Input Manipulation Vulnerabilities
References:
References:
- Timbuktu Pro Homepage (Timbuktu)
- Timbuktu Pro Remote Path Traversal and Log Injection (Core Security Technologies)
- CORE-2008-0204: Timbuktu Pro Remote Path Traversal and Log Injection (Core Security Technologies Advisories
) - Re: [Full-disclosure] Vulnerabilities in Timbuktu Pro 8.6.5 (
) - Re: [Full-disclosure] Vulnerabilities in Timbuktu Pro 8.6.5 (Luigi Auriemma
) - Vulnerabilities in Timbuktu Pro 8.6.5 (Luigi Auriemma
)