NNT Change Tracker and Remote Angel Insecure File Permissions Vulnerability
BID:48350
Info
NNT Change Tracker and Remote Angel Insecure File Permissions Vulnerability
| Bugtraq ID: | 48350 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 21 2011 12:00AM |
| Updated: | Jun 21 2011 12:00AM |
| Credit: | Secunia Research |
| Vulnerable: |
NNT Remote Angel 4.7 1 NNT Change Tracker 4.7.1 4 |
| Not Vulnerable: | |
Discussion
NNT Change Tracker and Remote Angel Insecure File Permissions Vulnerability
NNT Change Tracker and Remote Angel are prone to an insecure-file-permissions vulnerability.
An attacker may exploit this vulnerability to overwrite certain files in the 'Remote Angel' directory with arbitrary code. The arbitrary code will then run in the context of the programs using the affected package.
The issue affects the following versions:
NNT Change Tracker 4.7.1.4
NNT Remote Angel 4.7.0.1
Other versions may also be vulnerable.
NNT Change Tracker and Remote Angel are prone to an insecure-file-permissions vulnerability.
An attacker may exploit this vulnerability to overwrite certain files in the 'Remote Angel' directory with arbitrary code. The arbitrary code will then run in the context of the programs using the affected package.
The issue affects the following versions:
NNT Change Tracker 4.7.1.4
NNT Remote Angel 4.7.0.1
Other versions may also be vulnerable.
Exploit / POC
NNT Change Tracker and Remote Angel Insecure File Permissions Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
NNT Change Tracker and Remote Angel Insecure File Permissions Vulnerability
Solution:
Reportedly, vendor updates are available. Please contact the vendor for more information.
Solution:
Reportedly, vendor updates are available. Please contact the vendor for more information.
References
NNT Change Tracker and Remote Angel Insecure File Permissions Vulnerability
References:
References: