Dell EqualLogic CVE-2013-3304 Directory Traversal Vulnerability
BID:70760
Info
Dell EqualLogic CVE-2013-3304 Directory Traversal Vulnerability
| Bugtraq ID: | 70760 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3304 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2014 12:00AM |
| Updated: | Nov 10 2014 12:57AM |
| Credit: | Mauricio Correa |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Dell EqualLogic CVE-2013-3304 Directory Traversal Vulnerability
Dell EqualLogicis prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to gain access to arbitrary system files. Information harvested may aid in launching further attacks.
Dell EqualLogic Firmware versions 6.0 through 6.0.3 are vulnerable.
Dell EqualLogicis prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to gain access to arbitrary system files. Information harvested may aid in launching further attacks.
Dell EqualLogic Firmware versions 6.0 through 6.0.3 are vulnerable.
Exploit / POC
Dell EqualLogic CVE-2013-3304 Directory Traversal Vulnerability
An attacker can exploit this issue with a web browser.
An attacker can exploit this issue with a web browser.
Solution / Fix
Dell EqualLogic CVE-2013-3304 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or contact the vendor for more information.
Solution:
Updates are available. Please see the references or contact the vendor for more information.