Siemens SINEMA Server CVE-2014-2732 Directory Traversal Vulnerability
BID:66965
Info
Siemens SINEMA Server CVE-2014-2732 Directory Traversal Vulnerability
| Bugtraq ID: | 66965 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2732 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2014 12:00AM |
| Updated: | Apr 22 2014 01:00AM |
| Credit: | Vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Siemens SINEMA Server CVE-2014-2732 Directory Traversal Vulnerability
Siemens SINEMA server is prone to a directory-traversal vulnerability.
Exploiting this issue can allow an attacker to gain access to arbitrary files. Information harvested may aid in launching further attacks.
Versions prior to SINEMA server V12 SP1 are vulnerable.
Siemens SINEMA server is prone to a directory-traversal vulnerability.
Exploiting this issue can allow an attacker to gain access to arbitrary files. Information harvested may aid in launching further attacks.
Versions prior to SINEMA server V12 SP1 are vulnerable.
Exploit / POC
Siemens SINEMA Server CVE-2014-2732 Directory Traversal Vulnerability
An attacker can exploit the issue through a readily available tools.
An attacker can exploit the issue through a readily available tools.
Solution / Fix
Siemens SINEMA Server CVE-2014-2732 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Siemens SINEMA Server CVE-2014-2732 Directory Traversal Vulnerability
References:
References: