ES File Explorer Access Permissions Security Bypass Vulnerability
BID:52285
Info
ES File Explorer Access Permissions Security Bypass Vulnerability
| Bugtraq ID: | 52285 |
| Class: | Access Validation Error |
| CVE: |
CVE-2012-0322 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2012 12:00AM |
| Updated: | Mar 19 2015 09:34AM |
| Credit: | Shiongu of satoweb and Masafumi Horimoto of HOLLY & Co. Ltd. |
| Vulnerable: |
EStrongs, Inc ES File Explorer 1.6.1.1 EStrongs, Inc ES File Explorer 1.6.0.2 |
| Not Vulnerable: | |
Discussion
ES File Explorer Access Permissions Security Bypass Vulnerability
ES File Explorer is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions such as getting access to local files; this may aid in launching further attacks.
ES File Explorer versions 1.6.0.2 through 1.6.1.1 are vulnerable.
ES File Explorer is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions such as getting access to local files; this may aid in launching further attacks.
ES File Explorer versions 1.6.0.2 through 1.6.1.1 are vulnerable.
References
ES File Explorer Access Permissions Security Bypass Vulnerability
References:
References:
- ES File Explorer Homepage (EStrongs, Inc)
- JVN#08871006 ES File Explorer fails to restrict access permissions (Shiongu)