Sitecom Home Storage Center Multiple Security Vulnerabilities
BID:55516
Info
Sitecom Home Storage Center Multiple Security Vulnerabilities
| Bugtraq ID: | 55516 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2012 12:00AM |
| Updated: | Sep 11 2012 12:00AM |
| Credit: | Alcyon |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Sitecom Home Storage Center Multiple Security Vulnerabilities
Sitecom Home Storage Center is prone to the following security vulnerabilities because it fails to sufficiently sanitize user-supplied input:
1. An arbitrary file-upload vulnerability.
2. A command-injection vulnerability.
Successful exploits may allow an attacker to upload and execute arbitrary code in the context of the web server process or execute arbitrary commands as root. Other attacks are also possible.
Sitecom Home Storage Center is prone to the following security vulnerabilities because it fails to sufficiently sanitize user-supplied input:
1. An arbitrary file-upload vulnerability.
2. A command-injection vulnerability.
Successful exploits may allow an attacker to upload and execute arbitrary code in the context of the web server process or execute arbitrary commands as root. Other attacks are also possible.
Exploit / POC
Sitecom Home Storage Center Multiple Security Vulnerabilities
Attackers can exploit these issues through a browser.
The following exploit is available:
Attackers can exploit these issues through a browser.
The following exploit is available:
Solution / Fix
Sitecom Home Storage Center Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Sitecom Home Storage Center Multiple Security Vulnerabilities
References:
References: