PROMOTIC Multiple Security Vulnerabilities
BID:50133
Info
PROMOTIC Multiple Security Vulnerabilities
| Bugtraq ID: | 50133 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2011 12:00AM |
| Updated: | Oct 14 2011 12:00AM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
PROMOTIC PROMOTIC 8.1.3 |
| Not Vulnerable: | |
Discussion
PROMOTIC Multiple Security Vulnerabilities
PROMOTIC is prone to multiple security vulnerabilities.
Exploiting these issues may allow remote attackers to execute arbitrary code within the context of the affected application or disclose sensitive information.
PROMOTIC 8.1.3 is vulnerable; other versions may also be affected.
PROMOTIC is prone to multiple security vulnerabilities.
Exploiting these issues may allow remote attackers to execute arbitrary code within the context of the affected application or disclose sensitive information.
PROMOTIC 8.1.3 is vulnerable; other versions may also be affected.
Exploit / POC
PROMOTIC Multiple Security Vulnerabilities
The following example URI for the directory-traversal issue is available:
http://www.example.com/webdir/..\..\..\..\..\boot.ini
The researcher has created a proof-of-concept for the buffer-overflow issues. Please see the references for more information.
The following example URI for the directory-traversal issue is available:
http://www.example.com/webdir/..\..\..\..\..\boot.ini
The researcher has created a proof-of-concept for the buffer-overflow issues. Please see the references for more information.
Solution / Fix
PROMOTIC Multiple Security Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
PROMOTIC Multiple Security Vulnerabilities
References:
References:
- Product Homepage (PROMOTIC)
- PROMOTIC Multiple Vulnerabilities (Luigi Auriemma)
- Version 8.1.5 (from 28.11.2011) - stable version (Promotic)
- ICSA-12-024-02�??MICROSYS, SPOL. S R.O. PROMOTIC MULTIPLE VULNERABILITIES (ICS-CERT)