Alchemy Eye Remote Command Execution Vulnerability
BID:3599
Info
Alchemy Eye Remote Command Execution Vulnerability
| Bugtraq ID: | 3599 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0871 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered and posted to Bugtraq by Rapid 7 Security Advisories <[email protected]>. |
| Vulnerable: |
Alchemy Lab Alchemy Eye 3.0 Alchemy Lab Alchemy Eye 2.6 Alchemy Lab Alchemy Eye 2.5 Alchemy Lab Alchemy Eye 2.4 Alchemy Lab Alchemy Eye 2.3 Alchemy Lab Alchemy Eye 2.2 Alchemy Lab Alchemy Eye 2.1 Alchemy Lab Alchemy Eye 2.0 |
| Not Vulnerable: |
Alchemy Lab Alchemy Eye 3.0.11 |
Discussion
Alchemy Eye Remote Command Execution Vulnerability
Alchemy Eye is a network monitor tool for Windows based environments. Alchemy Eye is maintained by Alchemy Labs.
A directory traversal issue exists in Alchemy Eye which could allow for remote command execution.
Successful exploitation can lead to attackers gaining access to the host.
The vendor attempted to fix this vulnerability, however Alchemy Eye remains vulnerable. On patched systems, attackers can traverse out of the root directory by placing MS-DOS device names before the first "../".
Alchemy Eye is a network monitor tool for Windows based environments. Alchemy Eye is maintained by Alchemy Labs.
A directory traversal issue exists in Alchemy Eye which could allow for remote command execution.
Successful exploitation can lead to attackers gaining access to the host.
The vendor attempted to fix this vulnerability, however Alchemy Eye remains vulnerable. On patched systems, attackers can traverse out of the root directory by placing MS-DOS device names before the first "../".
Solution / Fix
Alchemy Eye Remote Command Execution Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.