HP SiteScope UploadFilesHandler Directory Traversal Vulnerability
BID:55273
Info
HP SiteScope UploadFilesHandler Directory Traversal Vulnerability
| Bugtraq ID: | 55273 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-3264 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2012 12:00AM |
| Updated: | Feb 14 2013 09:21PM |
| Credit: | Andrea Micalizzi aka rgod |
| Vulnerable: |
HP SiteScope 11.10 HP SiteScope 10.14 HP SiteScope 0 |
| Not Vulnerable: | |
Discussion
HP SiteScope UploadFilesHandler Directory Traversal Vulnerability
HP SiteScope is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to upload arbitrary files to the server.
Exploiting this issue may allow an attacker to upload arbitrary files to the server that could aid in further attacks.
HP SiteScope is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to upload arbitrary files to the server.
Exploiting this issue may allow an attacker to upload arbitrary files to the server that could aid in further attacks.
Exploit / POC
HP SiteScope UploadFilesHandler Directory Traversal Vulnerability
Attackers may exploit this issue through a browser.
The following exploit is available:
Attackers may exploit this issue through a browser.
The following exploit is available:
Solution / Fix
HP SiteScope UploadFilesHandler Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.