Argon Technology Client Management Services TFTP Server Directory Traversal Vulnerability
BID:28160
Info
Argon Technology Client Management Services TFTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 28160 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1281 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 08 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Luigi Auriemma is credited with the discovery of this vulnerability. |
| Vulnerable: |
Argon Technology Client Management Services 1.31 |
| Not Vulnerable: | |
Discussion
Argon Technology Client Management Services TFTP Server Directory Traversal Vulnerability
Argon Technology Client Management Services TFTP server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access arbitrary files outside of the TFTP server root directory. This can expose sensitive information that could help the attacker launch further attacks.
Client Management Services 1.31 and prior versions are vulnerable.
Argon Technology Client Management Services TFTP server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access arbitrary files outside of the TFTP server root directory. This can expose sensitive information that could help the attacker launch further attacks.
Client Management Services 1.31 and prior versions are vulnerable.
Exploit / POC
Argon Technology Client Management Services TFTP Server Directory Traversal Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Argon Technology Client Management Services TFTP Server Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].