Acronis Snap Deploy PXE Server TFTP Directory Traversal and Denial of Service Vulnerabilities
BID:28182
Info
Acronis Snap Deploy PXE Server TFTP Directory Traversal and Denial of Service Vulnerabilities
| Bugtraq ID: | 28182 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1411 CVE-2008-1410 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | Luigi Auriemma discovered these vulnerabilities. |
| Vulnerable: |
Acronis Snap Deploy 2.0.0.1076 |
| Not Vulnerable: | |
Discussion
Acronis Snap Deploy PXE Server TFTP Directory Traversal and Denial of Service Vulnerabilities
Acronis Snap Deploy is prone to a directory-traversal vulnerability and a denial-of-service vulnerability.
Exploiting these issues will allow attackers to obtain sensitive information or crash the affected application, denying further service to legitimate users.
Acronis Snap Deploy is prone to a directory-traversal vulnerability and a denial-of-service vulnerability.
Exploiting these issues will allow attackers to obtain sensitive information or crash the affected application, denying further service to legitimate users.
Exploit / POC
Acronis Snap Deploy PXE Server TFTP Directory Traversal and Denial of Service Vulnerabilities
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Acronis Snap Deploy PXE Server TFTP Directory Traversal and Denial of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Acronis Snap Deploy PXE Server TFTP Directory Traversal and Denial of Service Vulnerabilities
References:
References: