Nudester Unauthorized Arbitrary File Upload and Download Vulnerability
BID:3202
Info
Nudester Unauthorized Arbitrary File Upload and Download Vulnerability
| Bugtraq ID: | 3202 |
| Class: | Access Validation Error |
| CVE: |
CVE-2001-0966 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Discovered and posted to Bugtraq by Gary <[email protected]> on Aug 17, 2001. |
| Vulnerable: |
Nudester.org Nudester 1.10 |
| Not Vulnerable: |
Nudester.org Nudester 1.20 |
Discussion
Nudester Unauthorized Arbitrary File Upload and Download Vulnerability
A user downloading files from a Nudester host could gain access to a password, using a third party sniffer utility. Knowledge of this password could enable the user to log into the host and perform various actions, including uploading arbitrary files anywhere on the targets filesystem. As well, the user could traverse the directory structure of the host and download any file.
Successful exploitation of this vulnerability could lead to a complete compromise of the host's integrity.
A user downloading files from a Nudester host could gain access to a password, using a third party sniffer utility. Knowledge of this password could enable the user to log into the host and perform various actions, including uploading arbitrary files anywhere on the targets filesystem. As well, the user could traverse the directory structure of the host and download any file.
Successful exploitation of this vulnerability could lead to a complete compromise of the host's integrity.
Solution / Fix
Nudester Unauthorized Arbitrary File Upload and Download Vulnerability
Solution:
Nudester 1.20 has been released, which is reportedly not vulnerable.
Nudester.org Nudester 1.10
Solution:
Nudester 1.20 has been released, which is reportedly not vulnerable.
Nudester.org Nudester 1.10
-
Nudester Nudester 1.20
http://www.nudester.org/Files/Nudesterb.exe