vCenter Server Appliance CVE-2013-3080 Arbitrary File Upload Vulnerability
BID:59509
Info
vCenter Server Appliance CVE-2013-3080 Arbitrary File Upload Vulnerability
| Bugtraq ID: | 59509 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3080 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2013 12:00AM |
| Updated: | Apr 25 2013 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
VMWare vCenter Server Appliance 5.1 |
| Not Vulnerable: |
VMWare vCenter Server Appliance 5.1 Update 1 |
Discussion
vCenter Server Appliance CVE-2013-3080 Arbitrary File Upload Vulnerability
vCenter Server Appliance is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer. This can result in an arbitrary code execution within the context of the vulnerable application.
vCenter Server Appliance 5.1 is vulnerable.
vCenter Server Appliance is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer. This can result in an arbitrary code execution within the context of the vulnerable application.
vCenter Server Appliance 5.1 is vulnerable.
Exploit / POC
vCenter Server Appliance CVE-2013-3080 Arbitrary File Upload Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
vCenter Server Appliance CVE-2013-3080 Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
vCenter Server Appliance CVE-2013-3080 Arbitrary File Upload Vulnerability
References:
References:
- VMware Homepage (VMware)
- VMSA-2013-0006 VMware security updates for vCenter Server (VMware)