NeoAxis Web Player Zip File Directory Traversal Vulnerability
BID:51666
Info
NeoAxis Web Player Zip File Directory Traversal Vulnerability
| Bugtraq ID: | 51666 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-0907 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 25 2012 12:00AM |
| Updated: | Jan 25 2012 12:00AM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
NeoAxis NeoAxis Web Player 1.4 |
| Not Vulnerable: | |
Discussion
NeoAxis Web Player Zip File Directory Traversal Vulnerability
NeoAxis Web Player is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to extract files into directories of their choosing and overwrite arbitrary files. Successful exploits may aid in further attacks.
NeoAxis Web Player 1.4 is vulnerable; other versions may also be affected.
NeoAxis Web Player is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to extract files into directories of their choosing and overwrite arbitrary files. Successful exploits may aid in further attacks.
NeoAxis Web Player 1.4 is vulnerable; other versions may also be affected.
References
NeoAxis Web Player Zip File Directory Traversal Vulnerability
References:
References:
- NeoAxis Web Player Directory Traversal Vulnerability (Luigi Auriemma)
- NeoAxis Web Player Homepage (NeoAxis)