EMC ApplicationXtender Multiple Products Arbitrary File Upload Vulnerability
BID:55209
Info
EMC ApplicationXtender Multiple Products Arbitrary File Upload Vulnerability
| Bugtraq ID: | 55209 |
| Class: | Unknown |
| CVE: |
CVE-2012-2289 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2012 12:00AM |
| Updated: | Aug 29 2012 06:00PM |
| Credit: | Andrea Micalizzi (aka rgod) working with TippingPoint's Zero Day Initiative |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
EMC ApplicationXtender Multiple Products Arbitrary File Upload Vulnerability
EMC ApplicationXtender Multiple Products are prone to a vulnerability.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
The following products are vulnerable:
EMC ApplicationXtender Desktop versions prior to 6.5 SP2
EMC ApplicationXtender Web Access versions prior to 6.5 SP2
EMC ApplicationXtender Multiple Products are prone to a vulnerability.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
The following products are vulnerable:
EMC ApplicationXtender Desktop versions prior to 6.5 SP2
EMC ApplicationXtender Web Access versions prior to 6.5 SP2
Exploit / POC
EMC ApplicationXtender Multiple Products Arbitrary File Upload Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
EMC ApplicationXtender Multiple Products Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
EMC ApplicationXtender Multiple Products Arbitrary File Upload Vulnerability
References:
References: