ZeroShell 'cgi-bin/kerbynet' Local File Disclosure Vulnerability
BID:61771
Info
ZeroShell 'cgi-bin/kerbynet' Local File Disclosure Vulnerability
| Bugtraq ID: | 61771 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2013 12:00AM |
| Updated: | Aug 13 2013 12:00AM |
| Credit: | Yann CAM |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ZeroShell 'cgi-bin/kerbynet' Local File Disclosure Vulnerability
ZeroShell is prone to a local file-disclosure vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to obtain sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
ZeroShell 2.0.RC2 is vulnerable; other versions may also be affected.
ZeroShell is prone to a local file-disclosure vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to obtain sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
ZeroShell 2.0.RC2 is vulnerable; other versions may also be affected.
Exploit / POC
ZeroShell 'cgi-bin/kerbynet' Local File Disclosure Vulnerability
Attackers can exploit this issue using a browser.
The following example data and an exploit code is available:
Attackers can exploit this issue using a browser.
The following example data and an exploit code is available:
Solution / Fix
ZeroShell 'cgi-bin/kerbynet' Local File Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ZeroShell 'cgi-bin/kerbynet' Local File Disclosure Vulnerability
References:
References:
- ZeroShell Homepage (Fulvio Ricciardi)