EMC HomeBase Server Directory Traversal Remote Code Execution Vulnerability
BID:38380
Info
EMC HomeBase Server Directory Traversal Remote Code Execution Vulnerability
| Bugtraq ID: | 38380 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-0620 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2010 12:00AM |
| Updated: | Apr 28 2011 05:13PM |
| Credit: | Stephen Fewer of Harmony Security |
| Vulnerable: |
EMC HomeBase Server 6.3 EMC HomeBase Server 6.2 EMC HomeBase Server 0 |
| Not Vulnerable: |
EMC HomeBase Server 6.3.2 EMC HomeBase Server 6.2.3 |
Discussion
EMC HomeBase Server Directory Traversal Remote Code Execution Vulnerability
EMC HomeBase Server is prone to a remote code-execution vulnerability because it fails to properly sanitize user-supplied data.
An attacker can exploit this issue to overwrite arbitrary files and execute arbitrary code with the privileges of the service.
EMC HomeBase Server is prone to a remote code-execution vulnerability because it fails to properly sanitize user-supplied data.
An attacker can exploit this issue to overwrite arbitrary files and execute arbitrary code with the privileges of the service.
Exploit / POC
EMC HomeBase Server Directory Traversal Remote Code Execution Vulnerability
Attackers can use standard tools to exploit this issue.
The following exploit code is available:
Attackers can use standard tools to exploit this issue.
The following exploit code is available:
Solution / Fix
EMC HomeBase Server Directory Traversal Remote Code Execution Vulnerability
Solution:
Updates are available; please contact the vendor for more information.
Solution:
Updates are available; please contact the vendor for more information.
References
EMC HomeBase Server Directory Traversal Remote Code Execution Vulnerability
References:
References: