File Explorer CVE-2014-1973 Directory Traversal Vulnerability
BID:68726
Info
File Explorer CVE-2014-1973 Directory Traversal Vulnerability
| Bugtraq ID: | 68726 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1973 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2014 12:00AM |
| Updated: | Jul 18 2014 12:00AM |
| Credit: | Ryohei Koike of Sakura Information Systems |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
File Explorer CVE-2014-1973 Directory Traversal Vulnerability
File Explorer is prone to a directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to create or overwrite arbitrary files in the context of the application. This may aid in further attacks.
Versions prior to File Explorer 2.1.0.3 are vulnerable.
File Explorer is prone to a directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to create or overwrite arbitrary files in the context of the application. This may aid in further attacks.
Versions prior to File Explorer 2.1.0.3 are vulnerable.
Exploit / POC
File Explorer CVE-2014-1973 Directory Traversal Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
File Explorer CVE-2014-1973 Directory Traversal Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.