QNX Phgrafx File Enumeration Weakness
BID:66098
Info
QNX Phgrafx File Enumeration Weakness
| Bugtraq ID: | 66098 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2014 12:00AM |
| Updated: | Mar 10 2014 12:00AM |
| Credit: | cenobyte |
| Vulnerable: |
QNX QNX 6.5 QNX QNX 6.4.1 QNX QNX 6.3 QNX QNX 6.2 QNX QNX 6.5.0SP1 |
| Not Vulnerable: | |
Discussion
QNX Phgrafx File Enumeration Weakness
QNX Phgrafx is prone to a file-enumeration weakness.
An attacker can exploit this issue to enumerate the files present in the system's root directory; this may aid in further attacks.
QNX 6.5.0 SP1, 6.5.0, 6.4.1, 6.3.0, and 6.2.0 are vulnerable; other versions may also be affected.
QNX Phgrafx is prone to a file-enumeration weakness.
An attacker can exploit this issue to enumerate the files present in the system's root directory; this may aid in further attacks.
QNX 6.5.0 SP1, 6.5.0, 6.4.1, 6.3.0, and 6.2.0 are vulnerable; other versions may also be affected.
Exploit / POC
QNX Phgrafx File Enumeration Weakness
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The following Proof-of-concept is available:
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The following Proof-of-concept is available: