RSA Authentication Agent for Web Directory Traversal Vulnerability
BID:43406
Info
RSA Authentication Agent for Web Directory Traversal Vulnerability
| Bugtraq ID: | 43406 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-3261 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2010 12:00AM |
| Updated: | Sep 22 2010 12:00AM |
| Credit: | Tim Brown of Portcullis Computer Security |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
RSA Authentication Agent for Web Directory Traversal Vulnerability
RSA Authentication Agent for Web is prone to a directory-traversal vulnerability.
An attacker can exploit this issue to access arbitrary data protected by the RSA Authentication Agent.
The following are affected:
RSA Authentication Agent 7.0 for Web for Apache Web Server
RSA Authentication Agent 7.0 for Web for Internet Information Services
RSA Authentication Agent for Web is prone to a directory-traversal vulnerability.
An attacker can exploit this issue to access arbitrary data protected by the RSA Authentication Agent.
The following are affected:
RSA Authentication Agent 7.0 for Web for Apache Web Server
RSA Authentication Agent 7.0 for Web for Internet Information Services
Exploit / POC
RSA Authentication Agent for Web Directory Traversal Vulnerability
An attacker can exploit this issue with a web browser.
An attacker can exploit this issue with a web browser.
Solution / Fix
RSA Authentication Agent for Web Directory Traversal Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
RSA Authentication Agent for Web Directory Traversal Vulnerability
References:
References:
- RSA Homepage (RSA Security)