EMC RSA Archer GRC CVE-2013-0932 Arbitrary File Upload Vulnerability
BID:59669
Info
EMC RSA Archer GRC CVE-2013-0932 Arbitrary File Upload Vulnerability
| Bugtraq ID: | 59669 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0932 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2013 12:00AM |
| Updated: | May 06 2013 12:00AM |
| Credit: | EMC |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
EMC RSA Archer GRC CVE-2013-0932 Arbitrary File Upload Vulnerability
EMC RSA Archer GRC is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
This issue is fixed in version EMC RSA Archer GRC 5.3SP1.
EMC RSA Archer GRC is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
This issue is fixed in version EMC RSA Archer GRC 5.3SP1.
Exploit / POC
EMC RSA Archer GRC CVE-2013-0932 Arbitrary File Upload Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
EMC RSA Archer GRC CVE-2013-0932 Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
EMC RSA Archer GRC CVE-2013-0932 Arbitrary File Upload Vulnerability
References:
References: