Virtual Vertex Muster Web Interface Directory Traversal Vulnerability
BID:50841
Info
Virtual Vertex Muster Web Interface Directory Traversal Vulnerability
| Bugtraq ID: | 50841 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-4714 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2011 12:00AM |
| Updated: | Dec 13 2011 06:38PM |
| Credit: | Nick Freeman of Security-Assessment.com |
| Vulnerable: |
Virtual Vertex Virtual Vertex Muster 6.1.6 |
| Not Vulnerable: |
Virtual Vertex Virtual Vertex Muster 6.20 |
Discussion
Virtual Vertex Muster Web Interface Directory Traversal Vulnerability
Virtual Vertex Muster is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input submitted to its web interface.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the webserver. Information harvested may aid in launching further attacks.
Virtual Vertex Muster 6.1.6 is vulnerable; other versions may also be affected.
Virtual Vertex Muster is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input submitted to its web interface.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the webserver. Information harvested may aid in launching further attacks.
Virtual Vertex Muster 6.1.6 is vulnerable; other versions may also be affected.
Exploit / POC
Virtual Vertex Muster Web Interface Directory Traversal Vulnerability
An attacker can exploit this issue with a web browser.
The following example request is available:
GET /a\..\..\muster.db HTTP/1.1
An attacker can exploit this issue with a web browser.
The following example request is available:
GET /a\..\..\muster.db HTTP/1.1
Solution / Fix
Virtual Vertex Muster Web Interface Directory Traversal Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Virtual Vertex Muster Web Interface Directory Traversal Vulnerability
References:
References:
- Virtual Vertex Muster Homepage (Virtual Vertex)
- Virtual Vertex Muster Web Interface Directory Traversal Vulnerability (Virtual Vertex)