CoDeSys Gateway Server CVE-2012-4705 Directory Traversal Vulnerability
BID:59446
Info
CoDeSys Gateway Server CVE-2012-4705 Directory Traversal Vulnerability
| Bugtraq ID: | 59446 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-4705 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 19 2013 12:00AM |
| Updated: | Mar 19 2015 09:42AM |
| Credit: | Aaron Portnoy of Exodus Intelligence |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
CoDeSys Gateway Server CVE-2012-4705 Directory Traversal Vulnerability
CoDeSys Gateway Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Successful exploits will allow an attacker to create arbitrary files, which may then be executed to perform unauthorized actions. This may aid in further attacks.
Versions prior to CoDeSys 2.3.9.27 are vulnerable.
Note: This issue was previously discussed in BID 58032 (CoDeSys Gateway Server Multiple Security Vulnerabilities), but has been given its own record to better document it.
CoDeSys Gateway Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Successful exploits will allow an attacker to create arbitrary files, which may then be executed to perform unauthorized actions. This may aid in further attacks.
Versions prior to CoDeSys 2.3.9.27 are vulnerable.
Note: This issue was previously discussed in BID 58032 (CoDeSys Gateway Server Multiple Security Vulnerabilities), but has been given its own record to better document it.
Exploit / POC
CoDeSys Gateway Server CVE-2012-4705 Directory Traversal Vulnerability
An attacker can exploit this issue using a web browser.
The following exploit code is available:
An attacker can exploit this issue using a web browser.
The following exploit code is available:
Solution / Fix
CoDeSys Gateway Server CVE-2012-4705 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
CoDeSys Gateway Server CVE-2012-4705 Directory Traversal Vulnerability
References:
References:
- CoDeSys Homepage (3S - Smart Software Solutions)