Xerox DocuShare Weak Default Configuration Vulnerability
BID:5883
Info
Xerox DocuShare Weak Default Configuration Vulnerability
| Bugtraq ID: | 5883 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2002 12:00AM |
| Updated: | Oct 03 2002 12:00AM |
| Credit: | Discovery credited to Ryan Purita. |
| Vulnerable: |
Xerox DocuShare 2.2 |
| Not Vulnerable: | |
Discussion
Xerox DocuShare Weak Default Configuration Vulnerability
A vulnerability has be discovered in Xerox DocuShare v2.2.
Reportedly the default DocuShare configuration settings allow remote users to connect anonymously and access features that should otherwise be accessible by authenticated users only. Under default settings it is possible for an anonymous user to upload malicious files to the server.
It should be noted that it is not yet known whether later versions of the software are vulnerable to this issue.
A vulnerability has be discovered in Xerox DocuShare v2.2.
Reportedly the default DocuShare configuration settings allow remote users to connect anonymously and access features that should otherwise be accessible by authenticated users only. Under default settings it is possible for an anonymous user to upload malicious files to the server.
It should be noted that it is not yet known whether later versions of the software are vulnerable to this issue.
Exploit / POC
Xerox DocuShare Weak Default Configuration Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Xerox DocuShare Weak Default Configuration Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Xerox DocuShare Weak Default Configuration Vulnerability
References:
References: