SearchBlox 'name' Parameter Arbitrary File Overwrite Vulnerability
BID:61973
Info
SearchBlox 'name' Parameter Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 61973 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3598 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2013 12:00AM |
| Updated: | Aug 23 2013 12:00AM |
| Credit: | Ricky Roane Jr. |
| Vulnerable: |
SearchBlox SearchBlox 7.4 Build 1 |
| Not Vulnerable: |
SearchBlox SearchBlox 7.5 Build 1 |
Discussion
SearchBlox 'name' Parameter Arbitrary File Overwrite Vulnerability
SearchBlox is prone to a vulnerability that may allow attackers to overwrite arbitrary local files.
Successful exploits may allow an attacker to overwrite arbitrary local files and execute arbitrary code in the context of the user running the affected application.
SearchBlox 7.4 Build 1 is vulnerable; other versions may also be affected.
SearchBlox is prone to a vulnerability that may allow attackers to overwrite arbitrary local files.
Successful exploits may allow an attacker to overwrite arbitrary local files and execute arbitrary code in the context of the user running the affected application.
SearchBlox 7.4 Build 1 is vulnerable; other versions may also be affected.
Exploit / POC
SearchBlox 'name' Parameter Arbitrary File Overwrite Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
SearchBlox 'name' Parameter Arbitrary File Overwrite Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SearchBlox 'name' Parameter Arbitrary File Overwrite Vulnerability
References:
References:
- SearchBlox Homepage (SearchBlox Software)
- Vulnerability Note VU#592942 SearchBlox contains multiple vulnerabilities (Carnegie Mellon University)