Vordel Gateway Directory Traversal Vulnerability
BID:47975
Info
Vordel Gateway Directory Traversal Vulnerability
| Bugtraq ID: | 47975 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2011 12:00AM |
| Updated: | May 25 2011 12:00AM |
| Credit: | Brian W. Gary |
| Vulnerable: |
Vordel Limited Vordel Gateway 6.0.3 |
| Not Vulnerable: |
Vordel Limited Vordel Gateway 6.1 |
Discussion
Vordel Gateway Directory Traversal Vulnerability
Vordel Gateway is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
A remote attacker could exploit this vulnerability using directory-traversal strings (such as '../') to gain access to arbitrary files on the targeted system. This may result in the disclosure of sensitive information or lead to a complete compromise of the affected computer.
Vordel Gateway 6.0.3 is vulnerable; other versions may also be affected.
Vordel Gateway is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
A remote attacker could exploit this vulnerability using directory-traversal strings (such as '../') to gain access to arbitrary files on the targeted system. This may result in the disclosure of sensitive information or lead to a complete compromise of the affected computer.
Vordel Gateway 6.0.3 is vulnerable; other versions may also be affected.
Exploit / POC
Vordel Gateway Directory Traversal Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com:8090/manager/..%2f..%2f..%2f..%2f..%2f..%2fetc%2fshadow
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com:8090/manager/..%2f..%2f..%2f..%2f..%2f..%2fetc%2fshadow
Solution / Fix
Vordel Gateway Directory Traversal Vulnerability
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
Vordel Gateway Directory Traversal Vulnerability
References:
References:
- UPS-2011-0023: Vordel XML Gateway version 6.03 Directory Traversal (UpSploit)
- Vendor Homepage (Vordel Limited)