ES File Explorer CVE-2014-1970 Directory Traversal Vulnerability
BID:66384
Info
ES File Explorer CVE-2014-1970 Directory Traversal Vulnerability
| Bugtraq ID: | 66384 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1970 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2014 12:00AM |
| Updated: | Mar 20 2014 12:00AM |
| Credit: | Ryohei Koike of Sakura Information Systems |
| Vulnerable: |
ES APP Group ES File Explorer 3.0.0 |
| Not Vulnerable: |
ES APP Group ES File Explorer 3.0.4 |
Discussion
ES File Explorer CVE-2014-1970 Directory Traversal Vulnerability
ES File Explorer is prone to a directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to create or overwrite arbitrary files in the context of the application. This may aid in further attacks.
Versions prior to ES File Explorer 3.0.4 are vulnerable.
ES File Explorer is prone to a directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to create or overwrite arbitrary files in the context of the application. This may aid in further attacks.
Versions prior to ES File Explorer 3.0.4 are vulnerable.
Solution / Fix
ES File Explorer CVE-2014-1970 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ES File Explorer CVE-2014-1970 Directory Traversal Vulnerability
References:
References:
- ES File Explorer File Manager Homepage (ES APP Group)
- JVN#70029459 ES File Explorer vulnerable to directory traversal (IPA)
- JVNDB-2014-000033 ES File Explorer vulnerable to directory traversal (JPCERT/CC and IPA)