Omnicom Content Platform 'browser.asp' Parameter Directory Traversal Vulnerability
BID:31338
Info
Omnicom Content Platform 'browser.asp' Parameter Directory Traversal Vulnerability
| Bugtraq ID: | 31338 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5997 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2008 12:00AM |
| Updated: | Apr 16 2015 05:54PM |
| Credit: | AlbaniaN-[H] |
| Vulnerable: |
OCP Omnicom Content Platform 0 |
| Not Vulnerable: | |
Discussion
Omnicom Content Platform 'browser.asp' Parameter Directory Traversal Vulnerability
Omnicom Content Platform is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
To exploit this issue an attacker may need administrative privileges to the affected application.
Exploiting the issue may allow the attacker to obtain sensitive information that could aid in further attacks.
Omnicom Content Platform 2.0 is vulnerable; other versions may also be affected.
Omnicom Content Platform is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
To exploit this issue an attacker may need administrative privileges to the affected application.
Exploiting the issue may allow the attacker to obtain sensitive information that could aid in further attacks.
Omnicom Content Platform 2.0 is vulnerable; other versions may also be affected.
Exploit / POC
Omnicom Content Platform 'browser.asp' Parameter Directory Traversal Vulnerability
An attacker can exploit this issue with a browser.
The following example URI is available:
http://www.example.com/ocp/admin/fileKontrola/browser.asp?root=/
An attacker can exploit this issue with a browser.
The following example URI is available:
http://www.example.com/ocp/admin/fileKontrola/browser.asp?root=/
Solution / Fix
Omnicom Content Platform 'browser.asp' Parameter Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Omnicom Content Platform 'browser.asp' Parameter Directory Traversal Vulnerability
References:
References: