Blue Coat Reporter Directory Traversal Vulnerability
BID:49482
Info
Blue Coat Reporter Directory Traversal Vulnerability
| Bugtraq ID: | 49482 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2011 12:00AM |
| Updated: | Sep 06 2011 12:00AM |
| Credit: | Alejandro Hernandez (nitr0us), Chatsubo Labs |
| Vulnerable: |
Blue Coat Systems Blue Coat Reporter 9.2.4.1 Blue Coat Systems Blue Coat Reporter 9.2.3.1 Blue Coat Systems Blue Coat Reporter 9.2.3 Blue Coat Systems Blue Coat Reporter 9.2.0 Blue Coat Systems Blue Coat Reporter 9.1.5.1 Blue Coat Systems Blue Coat Reporter 9.1.1 |
| Not Vulnerable: |
Blue Coat Systems Blue Coat Reporter 9.3.1.1 |
Discussion
Blue Coat Reporter Directory Traversal Vulnerability
Blue Coat Reporter is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the Web server. Information harvested may aid in launching further attacks.
Blue Coat Reporter versions prior to 9.3 are vulnerable.
Blue Coat Reporter is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the Web server. Information harvested may aid in launching further attacks.
Blue Coat Reporter versions prior to 9.3 are vulnerable.
Exploit / POC
Blue Coat Reporter Directory Traversal Vulnerability
An attacker can use a Web browser to exploit this issue.
An attacker can use a Web browser to exploit this issue.
Solution / Fix
Blue Coat Reporter Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Blue Coat Reporter Directory Traversal Vulnerability
References:
References:
- Blue Coat Reporter Homepage (Blue Coat Systems)
- Blue Coat Systems Homepage (Blue Coat Systems)
- Reporter unauthenticated directory traversal (Blue Coat Systems)