Plex Media Server Directory Traversal and Authentication-Bypass Vulnerabilities
BID:65881
Info
Plex Media Server Directory Traversal and Authentication-Bypass Vulnerabilities
| Bugtraq ID: | 65881 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9181 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2014 12:00AM |
| Updated: | Dec 05 2014 12:56AM |
| Credit: | Stefan Viehböck of SEC Consult Vulnerability Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Plex Media Server Directory Traversal and Authentication-Bypass Vulnerabilities
Plex Media Server is prone to multiple directory-traversal vulnerabilities and an authentication-bypass vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow an attacker to bypass authentication and perform unauthorized actions on the affected application, and to obtain sensitive information that could aid in further attacks.
Plex Media Server is prone to multiple directory-traversal vulnerabilities and an authentication-bypass vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow an attacker to bypass authentication and perform unauthorized actions on the affected application, and to obtain sensitive information that could aid in further attacks.
Exploit / POC
Plex Media Server Directory Traversal and Authentication-Bypass Vulnerabilities
Attackers can exploit these issues via a browser.
The following example URIs and data are available:
Attackers can exploit these issues via a browser.
The following example URIs and data are available:
Solution / Fix
Plex Media Server Directory Traversal and Authentication-Bypass Vulnerabilities
Solution:
Reportedly these issues are fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly these issues are fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Plex Media Server Directory Traversal and Authentication-Bypass Vulnerabilities
References:
References: