Multiple Cybele Software Products Directory Traversal and Information Disclosure Vulnerabilities
BID:49919
Info
Multiple Cybele Software Products Directory Traversal and Information Disclosure Vulnerabilities
| Bugtraq ID: | 49919 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2011 12:00AM |
| Updated: | Oct 03 2011 12:00AM |
| Credit: | r () b13$ |
| Vulnerable: |
Cybele Software ThinVNC 2.0.0.1 Cybele Software ThinRDP 1.0.0.33 Cybele Software Access Point 2.0.0.1 |
| Not Vulnerable: | |
Discussion
Multiple Cybele Software Products Directory Traversal and Information Disclosure Vulnerabilities
Multiple Cybele Software products are prone to directory-traversal and information-disclosure vulnerabilities because the applications fail to sufficiently sanitize user-supplied input.
Exploiting the issues may allow an attacker to obtain sensitive information that could aid in further attacks.
The following products are affected:
ThinVNC 2.0.0.1
ThinRDP 1.0.0.33
ThinVNC Access Point 2.0.0.1
Multiple Cybele Software products are prone to directory-traversal and information-disclosure vulnerabilities because the applications fail to sufficiently sanitize user-supplied input.
Exploiting the issues may allow an attacker to obtain sensitive information that could aid in further attacks.
The following products are affected:
ThinVNC 2.0.0.1
ThinRDP 1.0.0.33
ThinVNC Access Point 2.0.0.1
Exploit / POC
Multiple Cybele Software Products Directory Traversal and Information Disclosure Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
Multiple Cybele Software Products Directory Traversal and Information Disclosure Vulnerabilities
Solution:
The vendor released an update. Please see the references for more information.
Solution:
The vendor released an update. Please see the references for more information.