WinWrapper Admin Server Arbitrary File Reading Vulnerability
BID:3219
Info
WinWrapper Admin Server Arbitrary File Reading Vulnerability
| Bugtraq ID: | 3219 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1139 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 21 2001 12:00AM |
| Updated: | Jan 31 2019 07:00PM |
| Credit: | This vulnerability was announced in an SNS Security Advisory on August 22, 2001. |
| Vulnerable: |
ASCII NT WinWrapper Professional 2.0 |
| Not Vulnerable: |
ASCII NT WinWrapper Professional 2.0.1 |
Discussion
WinWrapper Admin Server Arbitrary File Reading Vulnerability
WinWrapper is a commercial firewall implementation for the Microsoft Windows platform. It is distributed and maintained by ASCII NT.
WinWrapper provides a remote administration interface that runs on port 4096. Due to insufficient validation of input, it is possible for a remote user to traverse local directories on a system via the administrative interface using a classic dot-dot-slash (../) attack.
WinWrapper is a commercial firewall implementation for the Microsoft Windows platform. It is distributed and maintained by ASCII NT.
WinWrapper provides a remote administration interface that runs on port 4096. Due to insufficient validation of input, it is possible for a remote user to traverse local directories on a system via the administrative interface using a classic dot-dot-slash (../) attack.
Exploit / POC
WinWrapper Admin Server Arbitrary File Reading Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
WinWrapper Admin Server Arbitrary File Reading Vulnerability
Solution:
Updates available:
Solution:
Updates available:
References
WinWrapper Admin Server Arbitrary File Reading Vulnerability
References:
References: