TrustPort WebFilter 'help.php' Arbitrary File Access Vulnerability
BID:61662
Info
TrustPort WebFilter 'help.php' Arbitrary File Access Vulnerability
| Bugtraq ID: | 61662 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-5301 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2013 12:00AM |
| Updated: | Aug 20 2013 12:47PM |
| Credit: | oliver |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
TrustPort WebFilter 'help.php' Arbitrary File Access Vulnerability
TrustPort WebFilter is prone to an arbitrary file-access vulnerability.
An attacker can exploit this issue to read arbitrary files in the context of the web server process, which may aid in further attacks.
TrustPort WebFilter 5.5.0.2232 is vulnerable; other versions may also be affected.
TrustPort WebFilter is prone to an arbitrary file-access vulnerability.
An attacker can exploit this issue to read arbitrary files in the context of the web server process, which may aid in further attacks.
TrustPort WebFilter 5.5.0.2232 is vulnerable; other versions may also be affected.
Exploit / POC
TrustPort WebFilter 'help.php' Arbitrary File Access Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
TrustPort WebFilter 'help.php' Arbitrary File Access Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
TrustPort WebFilter 'help.php' Arbitrary File Access Vulnerability
References:
References: