InduSoft Web Studio Directory Traversal Vulnerability
BID:47842
Info
InduSoft Web Studio Directory Traversal Vulnerability
| Bugtraq ID: | 47842 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1900 |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2011 12:00AM |
| Updated: | May 12 2011 12:00AM |
| Credit: | Indusoft |
| Vulnerable: |
Indusoft Web Studio 7.0 Indusoft Web Studio 6.1 |
| Not Vulnerable: |
Indusoft Web Studio 7.0.1 04 |
Discussion
InduSoft Web Studio Directory Traversal Vulnerability
InduSoft Web Studio is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks.
InduSoft Web Studio versions prior to 6.1 and 7.0 are vulnerable.
InduSoft Web Studio is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks.
InduSoft Web Studio versions prior to 6.1 and 7.0 are vulnerable.
Exploit / POC
InduSoft Web Studio Directory Traversal Vulnerability
An attacker can exploit this issue with a web browser.
An attacker can exploit this issue with a web browser.
Solution / Fix
InduSoft Web Studio Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
InduSoft Web Studio Directory Traversal Vulnerability
References:
References:
- InduSoft Web Studio Home page (Indusoft)
- Security Updates and Hotfixes (Indusoft)