Openfiler Multiple Security Vulnerabilities
BID:67984
Info
Openfiler Multiple Security Vulnerabilities
| Bugtraq ID: | 67984 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2014 12:00AM |
| Updated: | Jun 10 2014 12:00AM |
| Credit: | dsa dsa |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Openfiler Multiple Security Vulnerabilities
Openfiler is prone to the following security vulnerabilities:
1. Multiple command-injection vulnerabilities
2. A directory traversal vulnerability
3. An information-disclosure weakness
4. An information-disclosure vulnerability
5. Multiple cross-site scripting vulnerabilities
An attacker can leverage these issues to execute arbitrary OS commands in context of the affected application, to view arbitrary local files, to gain access to potentially sensitive information or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may aid in further attacks.
Openfiler 2.99 is vulnerable; other versions may also be affected.
Openfiler is prone to the following security vulnerabilities:
1. Multiple command-injection vulnerabilities
2. A directory traversal vulnerability
3. An information-disclosure weakness
4. An information-disclosure vulnerability
5. Multiple cross-site scripting vulnerabilities
An attacker can leverage these issues to execute arbitrary OS commands in context of the affected application, to view arbitrary local files, to gain access to potentially sensitive information or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may aid in further attacks.
Openfiler 2.99 is vulnerable; other versions may also be affected.
Exploit / POC
Openfiler Multiple Security Vulnerabilities
Attackers can exploit these issues using a web browser.
The following exploit is available:
Attackers can exploit these issues using a web browser.
The following exploit is available:
Solution / Fix
Openfiler Multiple Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].