Sybase EAServer Unspecified Directory Traversal Vulnerability
BID:47987
Info
Sybase EAServer Unspecified Directory Traversal Vulnerability
| Bugtraq ID: | 47987 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2011 12:00AM |
| Updated: | Jun 07 2011 06:10PM |
| Credit: | Sow Ching Shiong working with iDefense Labs |
| Vulnerable: |
Sybase WorkSpace 2.5 Sybase WorkSpace 2.1.2 Sybase WorkSpace 2.1 Sybase WorkSpace 2.0 Sybase Replication Server Messaging Edition 15.2 Sybase EAServer 6.3.1 Sybase EAServer 6.3 Sybase EAServer 6.2 Sybase EAServer 6.0.2 Devel Edition Sybase EAServer 6.0 Sybase EAServer 5.5 Sybase EAServer 5.3 Sybase EAServer 5.2 Sybase EAServer 5.1 Sybase EAServer 5.0 Sybase Appeon 6.5 (English) Sybase Appeon 6.2 (Japanese) |
| Not Vulnerable: |
Sybase EAServer 6.3.1 ESD#4 Sybase EAServer 6.3.1 ESD#2 |
Discussion
Sybase EAServer Unspecified Directory Traversal Vulnerability
Sybase EAServer is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the webserver. Information harvested may aid in launching further attacks.
Sybase EAServer is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the webserver. Information harvested may aid in launching further attacks.
Exploit / POC
Sybase EAServer Unspecified Directory Traversal Vulnerability
An attacker can exploit this issue with a web browser.
An attacker can exploit this issue with a web browser.
Solution / Fix
Sybase EAServer Unspecified Directory Traversal Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
Sybase EAServer Unspecified Directory Traversal Vulnerability
References:
References: