IOServer Directory Traversal Vulnerability
BID:55093
Info
IOServer Directory Traversal Vulnerability
| Bugtraq ID: | 55093 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2012 12:00AM |
| Updated: | Aug 17 2012 12:00AM |
| Credit: | hinge |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IOServer Directory Traversal Vulnerability
IOServer is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
A remote attacker could exploit this vulnerability using directory-traversal strings (such as '../') to access arbitrary files within or outside of the XML server root directory. This could help the attacker launch further attacks.
IOServer 1.0.18.0 and prior versions are vulnerable.
IOServer is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
A remote attacker could exploit this vulnerability using directory-traversal strings (such as '../') to access arbitrary files within or outside of the XML server root directory. This could help the attacker launch further attacks.
IOServer 1.0.18.0 and prior versions are vulnerable.
Exploit / POC
IOServer Directory Traversal Vulnerability
Attackers can exploit this issue through a browser.
The following example URIs are available:
http://www.example.com/modbus.dll
http://www.example.com/
http://www.example.com/.../.../.../windows/repair/sam
http://www.example.com/.../.../.../windows/
Attackers can exploit this issue through a browser.
The following example URIs are available:
http://www.example.com/modbus.dll
http://www.example.com/
http://www.example.com/.../.../.../windows/repair/sam
http://www.example.com/.../.../.../windows/
Solution / Fix
IOServer Directory Traversal Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
IOServer Directory Traversal Vulnerability
References:
References: