Mollensoft Software Enceladus Server Suite Directory Traversal Vulnerability
BID:6338
Info
Mollensoft Software Enceladus Server Suite Directory Traversal Vulnerability
| Bugtraq ID: | 6338 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2002 12:00AM |
| Updated: | Dec 09 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "[email protected]" <[email protected]>. |
| Vulnerable: |
Mollensoft Software Enceladus Server Suite 3.9 Mollensoft Software Enceladus Server Suite 2.6.1 |
| Not Vulnerable: |
Mollensoft Software Enceladus Server Suite 3.9.11 |
Discussion
Mollensoft Software Enceladus Server Suite Directory Traversal Vulnerability
It has been reported that Enceladus fails to properly sanitize web requests. By sending a malicious web request to the vulnerable server, using directory traversal sequences, it is possible for a remote attacker to view and download sensitive resources located outside of the web root.
An attacker is able to traverse outside of the established web root by using dot-dot-slash (../) directory traversal sequences. An attacker may be able to obtain any web server readable files from outside of the web root directory.
It has been reported that Enceladus fails to properly sanitize web requests. By sending a malicious web request to the vulnerable server, using directory traversal sequences, it is possible for a remote attacker to view and download sensitive resources located outside of the web root.
An attacker is able to traverse outside of the established web root by using dot-dot-slash (../) directory traversal sequences. An attacker may be able to obtain any web server readable files from outside of the web root directory.
Exploit / POC
Mollensoft Software Enceladus Server Suite Directory Traversal Vulnerability
The following proof of concepts were provided by securma massine <[email protected]>:
ftp>cd cd @/....\
ftp> cd @@@@@@@@@@@/..c:\
The following proof of concepts were provided by securma massine <[email protected]>:
ftp>cd cd @/....\
ftp> cd @@@@@@@@@@@/..c:\
Solution / Fix
Mollensoft Software Enceladus Server Suite Directory Traversal Vulnerability
Solution:
The vendor has stated that Enceladus Server Suite 3.9.11 is not vulnerable to this issue. Users are advised to contact the vendor to obtain updates.
Solution:
The vendor has stated that Enceladus Server Suite 3.9.11 is not vulnerable to this issue. Users are advised to contact the vendor to obtain updates.
References
Mollensoft Software Enceladus Server Suite Directory Traversal Vulnerability
References:
References:
- Home Page (Mollensoft Software)
- Enceladus_Server_Suite_traversal_directory_vulnerability ("[email protected]"
) - Multiple vulnerability in Enceladus Server (securma massine
)