pfSense 'snort_log_view.php' Local File Include Vulnerability
BID:65181
Info
pfSense 'snort_log_view.php' Local File Include Vulnerability
| Bugtraq ID: | 65181 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 25 2014 12:00AM |
| Updated: | Feb 05 2014 12:24AM |
| Credit: | Pichaya Morimoto |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
pfSense 'snort_log_view.php' Local File Include Vulnerability
pfSense is prone to a local file-include vulnerability because it fails to adequately validate user-supplied input.
An attacker can exploit this vulnerability to execute arbitrary script code with escalated privileges. This could allow the attacker to compromise the application and the computer; other attacks are also possible.
pfSense 2.1 is vulnerable; other versions may also be affected.
pfSense is prone to a local file-include vulnerability because it fails to adequately validate user-supplied input.
An attacker can exploit this vulnerability to execute arbitrary script code with escalated privileges. This could allow the attacker to compromise the application and the computer; other attacks are also possible.
pfSense 2.1 is vulnerable; other versions may also be affected.
Exploit / POC
pfSense 'snort_log_view.php' Local File Include Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
pfSense 'snort_log_view.php' Local File Include Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
pfSense 'snort_log_view.php' Local File Include Vulnerability
References:
References:
- pfSense Homepage (BSD Perimeter LLC )