TeamSpeak 'help' Command Directory Traversal Vulnerability
BID:33256
Info
TeamSpeak 'help' Command Directory Traversal Vulnerability
| Bugtraq ID: | 33256 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2009 12:00AM |
| Updated: | Jan 16 2009 05:42PM |
| Credit: | c411k |
| Vulnerable: |
Teamspeak TeamSpeak Server 2.0.23 .17 Teamspeak TeamSpeak Server 2.0 |
| Not Vulnerable: | |
Discussion
TeamSpeak 'help' Command Directory Traversal Vulnerability
TeamSpeak is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Versions up to and including TeamSpeak 2.0.23.17 are vulnerable.
TeamSpeak is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Versions up to and including TeamSpeak 2.0.23.17 are vulnerable.
Exploit / POC
TeamSpeak 'help' Command Directory Traversal Vulnerability
An attacker can exploit this issue with a browser.
The following exploit is available:
An attacker can exploit this issue with a browser.
The following exploit is available:
Solution / Fix
TeamSpeak 'help' Command Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].