Sysax Multi Server 'SFTP' Module Multiple Denial Of Service Vulnerabilities
BID:41013
Info
Sysax Multi Server 'SFTP' Module Multiple Denial Of Service Vulnerabilities
| Bugtraq ID: | 41013 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2010 12:00AM |
| Updated: | Jun 28 2010 05:28PM |
| Credit: | leinakesi |
| Vulnerable: |
Codeorigin Sysax Multi Server 5.25 Codeorigin Sysax Multi Server 4.3 |
| Not Vulnerable: | |
Discussion
Sysax Multi Server 'SFTP' Module Multiple Denial Of Service Vulnerabilities
Sysax Multi Server is prone to multiple denial-of-service vulnerabilities.
An attacker with valid login credentials can exploit these issues to cause the server to crash, resulting in a denial-of-service condition. Other attacks may also be possible.
Sysax Multi Server 5.25 is vulnerable; prior versions may also be affected.
Update (June 28, 2010): Assuming the server is running as 'admin', attackers can execute arbitrary code to compromise the application.
Sysax Multi Server is prone to multiple denial-of-service vulnerabilities.
An attacker with valid login credentials can exploit these issues to cause the server to crash, resulting in a denial-of-service condition. Other attacks may also be possible.
Sysax Multi Server 5.25 is vulnerable; prior versions may also be affected.
Update (June 28, 2010): Assuming the server is running as 'admin', attackers can execute arbitrary code to compromise the application.
Exploit / POC
Sysax Multi Server 'SFTP' Module Multiple Denial Of Service Vulnerabilities
An attacker can use readily available network tools to exploit these issues.
The following exploit code is available:
An attacker can use readily available network tools to exploit these issues.
The following exploit code is available:
Solution / Fix
Sysax Multi Server 'SFTP' Module Multiple Denial Of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Sysax Multi Server 'SFTP' Module Multiple Denial Of Service Vulnerabilities
References:
References: