Adobe JRun 'logviewer.jsp' Directory Traversal Vulnerability
BID:36047
Info
Adobe JRun 'logviewer.jsp' Directory Traversal Vulnerability
| Bugtraq ID: | 36047 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-1873 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2009 12:00AM |
| Updated: | Oct 06 2009 03:49PM |
| Credit: | Digital Security Research Group |
| Vulnerable: |
Adobe JRun 4.0 Updater 7 |
| Not Vulnerable: | |
Discussion
Adobe JRun 'logviewer.jsp' Directory Traversal Vulnerability
Adobe JRun is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Adobe JRun 4 Updater 7 is vulnerable; prior versions may also be affected.
Adobe JRun is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Adobe JRun 4 Updater 7 is vulnerable; prior versions may also be affected.
Exploit / POC
Adobe JRun 'logviewer.jsp' Directory Traversal Vulnerability
An attacker can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/CuteSoft_Client/CuteEditor/Load.ashx?type=image&file=../../../web.config
An attacker can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/CuteSoft_Client/CuteEditor/Load.ashx?type=image&file=../../../web.config
Solution / Fix
Adobe JRun 'logviewer.jsp' Directory Traversal Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Adobe JRun 4.0 Updater 7
Solution:
The vendor has released an update. Please see the references for details.
Adobe JRun 4.0 Updater 7
-
Adobe jmc-app.ear
http://download.macromedia.com/pub/coldfusion/updates/jmc-app.ear -
Adobe jmc-app2.zip
http://download.macromedia.com/pub/coldfusion/updates/jmc-app2.zip
References
Adobe JRun 'logviewer.jsp' Directory Traversal Vulnerability
References:
References: