TRIDIUM NiagaraAX CVE-2012-4027 Directory Traversal Vulnerability
BID:54454
Info
TRIDIUM NiagaraAX CVE-2012-4027 Directory Traversal Vulnerability
| Bugtraq ID: | 54454 |
| Class: | Design Error |
| CVE: |
CVE-2012-4027 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2012 12:00AM |
| Updated: | Aug 13 2013 07:26AM |
| Credit: | Billy Rios and Terry McCorkle |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
TRIDIUM NiagaraAX CVE-2012-4027 Directory Traversal Vulnerability
TRIDIUM NiagaraAX is prone to a directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
TRIDIUM NiagaraAX is prone to a directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Exploit / POC
TRIDIUM NiagaraAX CVE-2012-4027 Directory Traversal Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
TRIDIUM NiagaraAX CVE-2012-4027 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
TRIDIUM NiagaraAX CVE-2012-4027 Directory Traversal Vulnerability
References:
References: