MicroWorld eScan Server Directory Traversal Vulnerability
BID:28127
Info
MicroWorld eScan Server Directory Traversal Vulnerability
| Bugtraq ID: | 28127 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1221 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Luigi Auriemma discovered this issue. |
| Vulnerable: |
MicroWorld Technologies eScan 9.0.742 .98 |
| Not Vulnerable: | |
Discussion
MicroWorld eScan Server Directory Traversal Vulnerability
MicroWorld eScan Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access arbitrary files outside of the FTP server root directory. This can expose sensitive information that could help the attacker launch further attacks.
eScan Server 9.0.742.98 is vulnerable to this issue; other versions may also be affected.
MicroWorld eScan Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access arbitrary files outside of the FTP server root directory. This can expose sensitive information that could help the attacker launch further attacks.
eScan Server 9.0.742.98 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
MicroWorld eScan Server Directory Traversal Vulnerability
Attackers can use readily available tools to exploit this issue.
The following URI demonstrates this issue:
ftp://SERVER:2021//windows/win.ini
Attackers can use readily available tools to exploit this issue.
The following URI demonstrates this issue:
ftp://SERVER:2021//windows/win.ini
Solution / Fix
MicroWorld eScan Server Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MicroWorld eScan Server Directory Traversal Vulnerability
References:
References:
- eScan Homepage (MicroWorld Technologies)
- Directory traversal in MicroWorld eScan Server 9.0.742.98 (Luigi Auriemma
)