Advantech Studio and Indusoft Web Studio 'NTWebServer.exe' Directory Traversal Vulnerability
BID:56871
Info
Advantech Studio and Indusoft Web Studio 'NTWebServer.exe' Directory Traversal Vulnerability
| Bugtraq ID: | 56871 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-1627 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2012 12:00AM |
| Updated: | Mar 08 2013 06:24PM |
| Credit: | Nin3 |
| Vulnerable: |
Indusoft Web Studio 7.0 Advantech Advantech Studio 7.0 |
| Not Vulnerable: | |
Discussion
Advantech Studio and Indusoft Web Studio 'NTWebServer.exe' Directory Traversal Vulnerability
Advantech Studio and Indusoft Web Studio are prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
A remote attacker can use directory-traversal strings to retrieve arbitrary files in the context of the affected application.
Versions Advantech Studio/Indusoft Web Studio 7.0 and prior are vulnerable.
Advantech Studio and Indusoft Web Studio are prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
A remote attacker can use directory-traversal strings to retrieve arbitrary files in the context of the affected application.
Versions Advantech Studio/Indusoft Web Studio 7.0 and prior are vulnerable.
Exploit / POC
Advantech Studio and Indusoft Web Studio 'NTWebServer.exe' Directory Traversal Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Advantech Studio and Indusoft Web Studio 'NTWebServer.exe' Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Advantech Studio and Indusoft Web Studio 'NTWebServer.exe' Directory Traversal Vulnerability
References:
References:
- Advantech Studio Homepage (Advantech)
- InduSoft Web Studio Homepage (VEVA Software, LLC. )
- ICS-ALERT-13-004-01 : ADVANTECH STUDIO DIRECTORY TRAVERSAL (ICS-CERT)
- ICSA-13-067-01 INDUSOFT ADVANTECH STUDIO DIR ECTORY TRAVERSAL (ICS-CERT)