PTK Arbitrary Command Execution and Cross Site Scripting Vulnerabilities
BID:34111
Info
PTK Arbitrary Command Execution and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 34111 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 13 2009 12:00AM |
| Updated: | Mar 16 2009 04:36PM |
| Credit: | Gabriele Zanoni |
| Vulnerable: |
DFLabs PTK 1.0.4 DFLabs PTK 1.0.3 DFLabs PTK 1.0.2 DFLabs PTK 1.0.1 |
| Not Vulnerable: |
DFLabs PTK 1.0.5 |
Discussion
PTK Arbitrary Command Execution and Cross Site Scripting Vulnerabilities
PTK is prone to a vulnerability that lets attackers execute arbitrary commands because it fails to properly sanitize user-supplied input. In addition, the application is prone to multiple unspecified cross-site scripting vulnerabilities.
An attacker may exploit these issues to execute arbitrary commands in the context of the vulnerable application. An attacker may also exploit some of these issues to execute arbitrary script code in the browser of a vulnerable user. Other attacks may also be possible.
PTK 1.0.1 through 1.0.4 are vulnerable.
PTK is prone to a vulnerability that lets attackers execute arbitrary commands because it fails to properly sanitize user-supplied input. In addition, the application is prone to multiple unspecified cross-site scripting vulnerabilities.
An attacker may exploit these issues to execute arbitrary commands in the context of the vulnerable application. An attacker may also exploit some of these issues to execute arbitrary script code in the browser of a vulnerable user. Other attacks may also be possible.
PTK 1.0.1 through 1.0.4 are vulnerable.
Exploit / POC
PTK Arbitrary Command Execution and Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI or opening a malicious HTML file.
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI or opening a malicious HTML file.
Solution / Fix
PTK Arbitrary Command Execution and Cross Site Scripting Vulnerabilities
Solution:
The vendor has released updates. Please contact the vendor for details.
DFLabs PTK 1.0.2
DFLabs PTK 1.0.3
DFLabs PTK 1.0.4
Solution:
The vendor has released updates. Please contact the vendor for details.
DFLabs PTK 1.0.2
-
DFLabs ptk-1.0.5.tar.gz
http://ovh.dl.sourceforge.net/sourceforge/ptk-forensics/ptk-1.0.5.tar. gz
DFLabs PTK 1.0.3
-
DFLabs ptk-1.0.5.tar.gz
http://ovh.dl.sourceforge.net/sourceforge/ptk-forensics/ptk-1.0.5.tar. gz
DFLabs PTK 1.0.4
-
DFLabs ptk-1.0.5.tar.gz
http://ovh.dl.sourceforge.net/sourceforge/ptk-forensics/ptk-1.0.5.tar. gz
References
PTK Arbitrary Command Execution and Cross Site Scripting Vulnerabilities
References:
References:
- PTK Homepage (DFLabs)
- What about Security? (DFLabs)
- Vulnerability Note VU#845747 (US-CERT)