Symantec Backup Exec System Recovery Manager Directory Traversal Vulnerability
BID:29350
Info
Symantec Backup Exec System Recovery Manager Directory Traversal Vulnerability
| Bugtraq ID: | 29350 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2512 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | Nicolas Pouvesle of Tenable Security |
| Vulnerable: |
Symantec Backup Exec System Recovery Manager 8.0.1 Symantec Backup Exec System Recovery Manager 8.0 Symantec Backup Exec System Recovery Manager 7.0.3 Symantec Backup Exec System Recovery Manager 7.0.2 Symantec Backup Exec System Recovery Manager 7.0.1 Symantec Backup Exec System Recovery Manager 7.0 |
| Not Vulnerable: |
Symantec Backup Exec System Recovery Manager 8.0.2 Symantec Backup Exec System Recovery Manager 7.0.4 |
Discussion
Symantec Backup Exec System Recovery Manager Directory Traversal Vulnerability
Symantec Backup Exec System Recovery Manager is prone to a directory-traversal vulnerability.
An attacker can exploit this issue to access privileged system files and gain unauthorized access to the affected computer.
This issue affects these versions:
Symantec Backup Exec System Recovery Manager 7 prior to 7.0.4
Symantec Back Exec System Recovery Manager 8 prior to 8.0.2.
Symantec Backup Exec System Recovery Manager is prone to a directory-traversal vulnerability.
An attacker can exploit this issue to access privileged system files and gain unauthorized access to the affected computer.
This issue affects these versions:
Symantec Backup Exec System Recovery Manager 7 prior to 7.0.4
Symantec Back Exec System Recovery Manager 8 prior to 8.0.2.
Exploit / POC
Symantec Backup Exec System Recovery Manager Directory Traversal Vulnerability
Attackers can exploit this issue by constructing and submitting a malicious request containing a directory-traversal string followed by a filename.
Attackers can exploit this issue by constructing and submitting a malicious request containing a directory-traversal string followed by a filename.
Solution / Fix
Symantec Backup Exec System Recovery Manager Directory Traversal Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
References
Symantec Backup Exec System Recovery Manager Directory Traversal Vulnerability
References:
References:
- Symantec Backup Exec System Recovery Homepage (Symantec)
- Symantec Security Advisory SYM08-013 (Symantec)