SMART Technologies SMART Board Unspecified Directory Traversal Vulnerability
BID:34045
Info
SMART Technologies SMART Board Unspecified Directory Traversal Vulnerability
| Bugtraq ID: | 34045 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2009 12:00AM |
| Updated: | Mar 11 2009 06:16PM |
| Credit: | David Marshall and r@b13$ from Digital Defense, Inc. Vulnerability Research Team |
| Vulnerable: |
SMART Technologies SMART Board 0 |
| Not Vulnerable: | |
Discussion
SMART Technologies SMART Board Unspecified Directory Traversal Vulnerability
SMART Technologies SMART Board is prone to an unspecified directory-traversal vulnerability because the device's webserver fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks.
We don't know which versions of SMART Board are affected. We will update this BID when more details emerge.
SMART Technologies SMART Board is prone to an unspecified directory-traversal vulnerability because the device's webserver fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks.
We don't know which versions of SMART Board are affected. We will update this BID when more details emerge.
Exploit / POC
SMART Technologies SMART Board Unspecified Directory Traversal Vulnerability
An attacker can exploit this issue via a browser.
An attacker can exploit this issue via a browser.
Solution / Fix
SMART Technologies SMART Board Unspecified Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SMART Technologies SMART Board Unspecified Directory Traversal Vulnerability
References:
References: